Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   GMX-Adresse verschickt mails in meinem Namen! Habe ich einen Trojaner? (https://www.trojaner-board.de/130142-gmx-adresse-verschickt-mails-meinem-namen-habe-trojaner.html)

Sophie_S. 26.01.2013 20:34

GMX-Adresse verschickt mails in meinem Namen! Habe ich einen Trojaner?
 
Hi erstmal an alle. Ich bin neu hier und kenne mich leider überhaupt nicht mit dem Thema Viren etc. aus (eigentlich auch nicht wirklich mit Computern...). Als ich heute ein von mir selten genutztes e-mail Konto überprüft habe, hatte ich eine Antwortnachricht von einem Freund auf eine e-mail, die ich nicht geschrieben hatte. Dabei handelte es sich offensichtlich um Spam, der von meiner e-mail Adresse verschickt wurde. Zudem hatte ich mehrere e-mails, die mir sagten, dass weitere Spam mails nicht an die Adressaten zugestellt werden konnten. In anderen Foren habe ich gelesen, dass letztes Jahr (ca 07.2012) viele GMX-Konten geknackt wurden, allerdings war die auch mit der Anzeige vieler Fehlerhafter Logins verbunden. Das war bei mir nicht der Fall. Das ist der Header der ursprünglichen mail:

--- The header of the original message is following. ---

Received: from mailout-de.gmx.net ([10.1.76.31]) by mrigmx.server.lan
(mrigmx001) with ESMTP (Nemesis) id 0LfDle-1UnH1I2vBw-00oo9W for
<xxx@gmx.de>; Fri, 25 Jan 2013 21:43:32 +0100
Received: (qmail 8683 invoked by uid 0); 25 Jan 2013 20:43:32 -0000
Received: from 41.225.63.255 by www012.gmx.net with HTTP;
Fri, 25 Jan 2013 21:43:31 +0100 (CET)
Content-Type: text/plain; charset="utf-8"
Date: Fri, 25 Jan 2013 21:43:31 +0100
From: "xxx xxx" <xxx@gmx.de>
Message-ID: <20130125204331.282980@gmx.net>
MIME-Version: 1.0
To: xxx@gmx.de
X-Authenticated: #31487051
X-Flags: 0001
X-Mailer: WWW-Mail 6100 (Global Message Exchange)
X-Priority: 3
X-Provags-ID: V01U2FsdGVkX19aH4EtLjNaAziY7McQXRhVZ5ZCv3BDezItddibut
af6QvqoLJtO/tIGyH0bLa+w+Jk9zDbrpKlNg==
Content-Transfer-Encoding: 8bit
X-GMX-UID: JItwce4PeSEqWioXi3UhrOp+IGRvb0Aj


Die Namen hab ich mal durch xxx ersetzt.
Ich hab leider keine Ahnung, was ich damit anfangen soll. :confused: Habe ich einen Trojaner auf meinem Computer? Mein Passwort habe ich ntürlich sofort geändert. Ich habe jetzt mal eine vollständige Untersuchung von Kaspersky gestartet, die dauert aber leider noch ca 20 Stunden. Ist das normal?
Sorry für die vielen Fragen. Nur leider bin ich sehr verunsichert. Wurde mein Passwort geknackt, oder habe ich einen Trojaner? Und sind meine anderen Passwörter jetzt auch gefährdet? Z.B. Paypal, ebay... Die sind allerdings etwas komplizierter
Viele Dank für eure Hilfe
Sophie

cosinus 27.01.2013 00:36

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner?
Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Sophie_S. 27.01.2013 00:46

Hallo Cosinus,
Vielen Dank für deine Antwort! Ich habe jetzt Malwarebytes installiert und durchlaufen lassen. Hier ist das Log File
Code:

Malwarebytes Anti-Malware (Test) 1.70.0.1100
www.malwarebytes.org

Datenbank Version: v2013.01.26.10

Windows Vista x86 NTFS
Internet Explorer 8.0.6001.18904
xxx yyy :: xxx-PC [Administrator]

Schutz: Aktiviert

26.01.2013 22:19:04
mbam-log-2013-01-26 (22-19-04).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212269
Laufzeit: 1 Stunde(n), 5 Minute(n), 48 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\Users\xxx yyy\AppData\Local\Temp\ICReinstall\PDFCreatorSetup.exe (Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\xxx yyy\AppData\Local\Temp\49406733.Uninstall\Uninstall.exe (Adware.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

2 schädliche Dateien wurden gefunden, soweit ich das erkennen konnte. Nur mehr kann ich leider nicht damit anfangen. Vielen lieben Dank nochmal

cosinus 27.01.2013 01:00

Hast du

"Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs posten!"

nicht gelesen oder nicht verstanden? :wtf:

Sophie_S. 27.01.2013 01:51

Hallo Cosinus,
doch gelesen hatte ich es schon und eigentlich auch verstanden. Ich hatte den Scan nur schon gemacht (nach Anweisung des Forum, vielleicht hatte ich das missverstanden). Und da es der einzige war den ich hatte hab ich ihn einfach mal hochgeladen :-(.
War das schlimm?
LG

cosinus 27.01.2013 13:26

Oh sry, dann hab ich das falsch verstanden.
Hast du noch weitere Logs mit Funden?

Sophie_S. 27.01.2013 15:34

Wenn ich meinen Post lese muss ich sagen, dass ich mich auch ziemlich missverständlich ausgedrückt habe. :pfeiff:
Nein leider nicht. Ich habe zwar Kaspersky laufen lassen (auch nur die schnelle Untersuchung, die andere hab ich irgendwann abgebrochen weil es zu lange gedauert hat), nur leider weiß ich nicht, wo ich da das Lg file finde. Kaspersky findet allerdings auch keine Bedrohungen. Sollte ich noch weitere Programme runterladen und durchlaufen lassen?
Viele Grüße
Sophie
ps mein Internet läuft jetzt auch wieder besser.

cosinus 28.01.2013 11:12

Bevor wir uns an die Arbeit machen, möchte ich dich bitten, folgende Punkte vollständig und aufmerksam zu lesen.
  • Lies dir meine Anleitungen, die ich im Laufe dieses Strangs hier posten werde, aufmerksam durch. Frag umgehend nach, wenn dir irgendetwas unklar sein sollte, bevor du anfängst meine Anleitungen umzusetzen.

  • Solltest du bei einem Schritt Probleme haben, stoppe dort und beschreib mir das Problem so gut du kannst. Manchmal erfordert ein Schritt den vorhergehenden.

  • Bitte nur Scans durchführen zu denen du von einem Helfer aufgefordert wurdest! Installiere / Deinstalliere keine Software ohne Aufforderung!

  • Poste die Logfiles direkt in deinen Thread (bitte in CODE-Tags) und nicht als Anhang, ausser du wurdest dazu aufgefordert. Logs in Anhängen erschweren mir das Auswerten!

  • Beachte bitte auch => Löschen von Logfiles und andere Anfragen

Note:
Sollte ich drei Tage nichts von mir hören lassen, so melde dich bitte in diesem Strang => Erinnerung an meinem Thread.
Nervige "Wann geht es weiter" Nachrichten enden mit Schließung deines Themas. Auch ich habe ein Leben abseits des Trojaner-Boards.


Erstmal eine Kontrolle mit OTL bitte:
  • Doppelklick auf die OTL.exe
  • Vista User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in CODE-Tags in den Thread.

Sophie_S. 28.01.2013 21:51

Hallo Cosinus,
ich hab OTL durchlaufen lassen. Hier sind die Lof Files
Code:

OTL logfile created on: 28.01.2013 20:45:49 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\xxx yyy\Downloads
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 57,58% Memory free
6,19 Gb Paging File | 4,45 Gb Available in Paging File | 71,85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 78,37 Gb Free Space | 54,39% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 128,76 Gb Free Space | 89,42% Space Free | Partition Type: NTFS
 
Computer Name: xxx-PC | User Name: xxx yyy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\xxx yyy\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\xxx yyy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Programme\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Programme\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programme\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Programme\devolo\dlan\devolonetsvc.exe (devolo AG)
PRC - C:\Programme\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
PRC - C:\Programme\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
PRC - C:\Programme\RayV\RayV\RayV.exe (RayV)
PRC - C:\Programme\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
PRC - C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Programme\Samsung\Samsung Recovery Solution II\WCScheduler.exe ()
PRC - C:\Programme\Samsung\EBM\EasyBatteryMgr3.exe (SAMSUNG Electronics co., LTD.)
PRC - C:\Programme\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Programme\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Programme\Samsung\Easy Display Manager\dmhkcore.exe (SAMSUNG Electronics)
PRC - C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\libglesv2.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\libegl.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\ffmpegsumo.dll ()
MOD - C:\Users\xxx yyy\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Updater.DEU ()
MOD - C:\Users\xxx yyy\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_rdlang32.deu ()
MOD - C:\Programme\Adobe\Reader 10.0\Reader\sqlite.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Programme\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Programme\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Programme\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
MOD - C:\Programme\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\QtGui4.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\QtCore4.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\localization_manager.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03858406f9a9514402888707e8b93abe\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\23281812ddf7a1fab881b5322e577ac4\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7208ffa39630e9b923331f9df0947a12\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1941d7639299344ae28fb6b23da65247\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6312464f64727a2a50d5ce3fd73ad1bb\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\52e1ea3c7491e05cda766d7b3ce3d559\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll ()
MOD - C:\Programme\Kaspersky Lab\Kaspersky PURE\dblite.dll ()
MOD - C:\Programme\RayV\RayV\libsctp.dll ()
MOD - C:\Programme\RayV\RayV\avcodec-52.dll ()
MOD - C:\Programme\RayV\RayV\avutil-50.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_de_b77a5c561934e089\System.Windows.Forms.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_de_b77a5c561934e089\mscorlib.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2767.37205__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2767.37261__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2767.37239__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2767.37261__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2767.37247__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2767.37462__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2767.37420__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2767.37224__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2767.37499__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2767.37429__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2767.37504__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2767.37434__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2767.37218__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2767.37428__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2767.37491__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2767.37365__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2767.37275__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2767.37225__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2767.37447__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2767.37281__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2767.37268__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2767.37386__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2767.37281__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2767.37385__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2767.37357__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2767.37407__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2767.37406__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2767.37194__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2767.37195__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2767.37491__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2767.37280__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2767.37194__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2767.37260__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2767.37190__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2767.37427__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2767.37497__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2767.37362__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2767.37485__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2767.37193__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2767.37453__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2767.37385__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2767.37204__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2767.37189__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2767.37238__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2767.37217__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2767.37191__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2767.37203__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2767.37204__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2767.37192__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2767.37193__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2767.37204__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2767.37462__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2767.37355__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2767.37342__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2767.37419__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2767.37224__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2767.37223__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2767.37223__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2767.37341__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2767.37190__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2767.37190__90ba9c70f846762e\AEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2767.37195__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray.resources\2.0.2767.37476_de_90ba9c70f846762e\CLI.Component.Systemtray.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2767.37525__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2767.37194__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2767.37485__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2767.37483__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2767.37192__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2767.37192__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2767.37233__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2767.37231__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2767.37193__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2767.37476__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2767.37196__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2767.37194__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2767.37210__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2767.37213__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2767.37204__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2767.37210__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2767.37484__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2767.37253__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2767.37195__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Programme\Samsung\Samsung Recovery Solution II\WCScheduler.exe ()
MOD - C:\Programme\Samsung\Samsung Recovery Solution II\Resdll.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Windows\System32\btwhidcs.dll ()
MOD - C:\Programme\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Programme\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\WinMove.dll ()
MOD - C:\Programme\Samsung\Samsung Magic Doctor\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\EasySpeedUpManager\HookDllPS2.dll ()
MOD - C:\Programme\Samsung\Easy Display Manager\HookDllPS2.dll ()
 
 
========== Services (SafeList) ==========
 
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Programme\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Programme\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) -- C:\Programme\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (MozillaMaintenance) -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (odserv) -- C:\Programme\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (DevoloNetworkService) -- C:\Programme\devolo\dlan\devolonetsvc.exe (devolo AG)
SRV - (AVP) -- C:\Programme\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
SRV - (CSObjectsSrv) -- C:\Programme\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (CVPND) -- C:\Programme\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (MSSQL$MSSMLBIZ) -- C:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (OMSI download service) -- C:\Programme\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe ()
SRV - (BcmSqlStartupSvc) -- C:\Programme\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (SQLWriter) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (SQLBrowser) -- C:\Programme\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper) -- C:\Programme\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (WinDefend) -- C:\Programme\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Samsung Update Plus) -- C:\Programme\Samsung\Samsung Update Plus\SLUBackgroundService.exe ()
SRV - (WMPNetworkSvc) -- C:\Programme\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (ose) -- C:\Programme\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (AgereModemAudio) -- C:\Windows\System32\agrsmsvc.exe (Agere Systems)
 
 
========== Driver Services (SafeList) ==========
 
DRV - (VMC302) -- System32\Drivers\VMC302.sys File not found
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (MBAMProtector) -- C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (NPF_devolo) -- C:\Windows\System32\drivers\npf_devolo.sys (CACE Technologies)
DRV - (CSCrySec) -- C:\Windows\System32\drivers\CSCrySec.sys (Infowatch)
DRV - (CSVirtualDiskDrv) -- C:\Windows\System32\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV - (KLBG) -- C:\Windows\System32\drivers\klbg.sys (Kaspersky Lab)
DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (kl1) -- C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (CVPNDRVA) -- C:\Windows\System32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (s1029unic) -- C:\Windows\System32\drivers\s1029unic.sys (MCCI Corporation)
DRV - (s1029mdm) -- C:\Windows\System32\drivers\s1029mdm.sys (MCCI Corporation)
DRV - (s1029bus) -- C:\Windows\System32\drivers\s1029bus.sys (MCCI Corporation)
DRV - (s1029mdfl) -- C:\Windows\System32\drivers\s1029mdfl.sys (MCCI Corporation)
DRV - (s1029mgmt) -- C:\Windows\System32\drivers\s1029mgmt.sys (MCCI Corporation)
DRV - (s1029obex) -- C:\Windows\System32\drivers\s1029obex.sys (MCCI Corporation)
DRV - (s1029nd5) -- C:\Windows\System32\drivers\s1029nd5.sys (MCCI Corporation)
DRV - (DNE) -- C:\Windows\System32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (KMDFMEMIO) -- C:\Windows\System32\drivers\KMDFMEMIO.sys (SAMSUNG ELECTRONICS CO., LTD.)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (RTL8187) -- C:\Windows\System32\drivers\RTL8187.sys (Realtek Semiconductor Corporation                          )
DRV - (AtiPcie) -- C:\Windows\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)
DRV - (CVirtA) -- C:\Windows\System32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (NETw2v32) -- C:\Windows\System32\drivers\NETw2v32.sys (Intel® Corporation)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation                          )
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
 
 
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
 
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://mystart.incredimail.com/mb68?u=92541582143120950
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - No CLSID value found
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = hxxp://mystart.incredimail.com/mb68/?search={searchTerms}&loc=search_box&u=92541582143120950
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "hxxp://mystart.incredimail.com/mb68?u=92541582143120950"
FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.8
FF - prefs.js..extensions.enabledAddons: toolbar@web.de:2.3.4
FF - prefs.js..extensions.enabledItems: KavAntiBanner@Kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: linkfilter@kaspersky.ru:11.0.0.232
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&q="
 
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rayv.com/rayvplugin: C:\Program Files\RayV\RayV\plugins\nprayvplugin.dll (RayV)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: c:\Program Files\Sony\Media Go\npmediago.dll (Sony Creative Software Inc)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\xxx yyy\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\xxx yyy\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012.09.02 01:47:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012.08.29 23:32:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky PURE\THBExt [2011.08.19 15:36:50 | 000,000,000 | ---D | M]
 
[2009.12.31 00:54:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx yyy\AppData\Roaming\mozilla\Extensions
[2013.01.13 14:58:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\xxx yyy\AppData\Roaming\mozilla\Firefox\Profiles\n81mkgky.default\extensions
[2010.09.29 15:15:24 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\xxx yyy\AppData\Roaming\mozilla\Firefox\Profiles\n81mkgky.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012.07.13 17:50:51 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\xxx yyy\AppData\Roaming\mozilla\Firefox\Profiles\n81mkgky.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}(211)
[2010.07.26 20:15:10 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\xxx yyy\AppData\Roaming\mozilla\Firefox\Profiles\n81mkgky.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012.12.12 08:41:39 | 000,559,819 | ---- | M] () (No name found) -- C:\Users\xxx yyy\AppData\Roaming\mozilla\firefox\profiles\n81mkgky.default\extensions\toolbar@web.de.xpi
[2010.07.26 21:17:11 | 000,000,873 | ---- | M] () -- C:\Users\xxx yyy\AppData\Roaming\mozilla\firefox\profiles\n81mkgky.default\searchplugins\conduit.xml
[2011.09.27 17:59:11 | 000,002,207 | ---- | M] () -- C:\Users\xxx yyy\AppData\Roaming\mozilla\firefox\profiles\n81mkgky.default\searchplugins\MyStart Search.xml
[2012.09.02 01:46:47 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.08.19 15:40:57 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Programme\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
[2012.09.02 01:46:47 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\distribution\extensions
[2012.09.02 01:46:48 | 000,000,000 | ---D | M] (WEB.DE MailCheck) -- C:\Programme\Mozilla Firefox\distribution\extensions\toolbar@web.de
[2012.08.25 03:00:05 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010.07.17 04:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012.08.25 03:49:52 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012.08.25 03:49:52 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012.08.25 03:49:52 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012.08.25 03:49:52 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012.08.25 03:49:52 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012.08.25 03:49:52 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
 
========== Chrome  ==========
 
CHR - homepage: hxxp://www.google.de/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.de/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\xxx yyy\AppData\Local\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: RayV Plugin (Enabled) = C:\Program Files\RayV\RayV\plugins\nprayvplugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Media Go Detector (Enabled) = c:\Program Files\Sony\Media Go\npmediago.dll
CHR - Extension: YouTube = C:\Users\xxx yyy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google-Suche = C:\Users\xxx yyy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: Google Mail = C:\Users\xxx yyy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2006.09.18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1      localhost
O1 - Hosts: ::1            localhost
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programme\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-405802704-1985627685-3967156141-1003\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Programme\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Programme\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Programme\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-405802704-1985627685-3967156141-1003..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe (RayV)
O4 - HKU\S-1-5-21-405802704-1985627685-3967156141-1003..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000 File not found
O4 - HKU\S-1-5-21-405802704-1985627685-3967156141-1003..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-405802704-1985627685-3967156141-1003..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Users\xxx yyy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\xxx yyy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\xxx yyy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk = C:\Programme\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoHotStart = 0
O8 - Extra context menu item: Free YouTube Download - C:\Users\xxx yyy\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Hinzufügen zu Anti-Banner - C:\Programme\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O8 - Extra context menu item: Nach Microsoft E&xel exportieren - C:\Programme\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: &Virtuelle Tastatur - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programme\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Li&nks untersuchen - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{06024DAB-99FC-4F21-9E86-F61C16A2F336}: DhcpNameServer = 83.136.192.3 83.136.198.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39A07E04-7A39-4648-AA69-DE454E4CA2E1}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Programme\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programme\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Programme\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Programme\Kaspersky Lab\Kaspersky PURE\kloehk.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Programme\Kaspersky Lab\Kaspersky PURE\mzvkbd3.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O24 - Desktop WallPaper: C:\Users\xxx yyy\Pictures\2008-09-09\009.JPG
O24 - Desktop BackupWallPaper: C:\Users\xxx yyy\Pictures\2008-09-09\009.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 22:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{1f0257c4-05f9-11e0-a82b-0013779d450b}\Shell - "" = AutoRun
O33 - MountPoints2\{1f0257c4-05f9-11e0-a82b-0013779d450b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{67f9cac6-561b-11e2-9660-0013779d450b}\Shell\AutoRun\command - "" = F:\Menu.exe
O33 - MountPoints2\{8325cefa-6308-11e2-b35f-0013779d450b}\Shell\AutoRun\command - "" = F:\Menu.exe
O33 - MountPoints2\{8a7bf9f0-98f2-11df-ba8a-0013779d450b}\Shell - "" = AutoRun
O33 - MountPoints2\{8a7bf9f0-98f2-11df-ba8a-0013779d450b}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{f8351ce1-5021-11e2-bae6-0013779d450b}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toshiba Places.html
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.01.26 22:14:03 | 000,000,000 | ---D | C] -- C:\Users\xxx yyy\AppData\Roaming\Malwarebytes
[2013.01.26 22:10:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.01.26 22:10:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.01.26 22:10:11 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013.01.26 22:10:10 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.01.15 02:35:55 | 000,000,000 | ---D | C] -- C:\Users\xxx yyy\Desktop\Seminar
[2013.01.10 03:09:20 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2010.07.26 22:15:02 | 000,148,736 | ---- | C] (Avanquest Software) -- C:\ProgramData\hpe872A.dll
 
========== Files - Modified Within 30 Days ==========
 
[2013.01.28 21:06:00 | 000,000,442 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{CBF9D235-EE3E-434C-B2FF-CAC88B3CDD7F}.job
[2013.01.28 21:04:01 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.01.28 21:01:52 | 000,003,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013.01.28 21:01:52 | 000,003,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013.01.28 20:39:00 | 000,001,168 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-405802704-1985627685-3967156141-1003UA.job
[2013.01.28 20:33:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.01.28 19:02:01 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.01.28 19:02:01 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\Registry Reviver-xxx yyy-Startup.job
[2013.01.28 19:01:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.01.28 19:01:27 | 3219,308,544 | -HS- | M] () -- C:\hiberfil.sys
[2013.01.28 03:10:26 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013.01.27 03:39:00 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-405802704-1985627685-3967156141-1003Core.job
[2013.01.26 22:10:24 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.25 19:01:01 | 000,000,963 | ---- | M] () -- C:\Users\xxx yyy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.01.25 18:37:55 | 000,002,102 | ---- | M] () -- C:\Users\xxx yyy\Desktop\Google Chrome.lnk
[2013.01.23 16:08:02 | 000,000,913 | ---- | M] () -- C:\Users\xxx yyy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2013.01.23 00:46:51 | 000,011,430 | ---- | M] () -- C:\Users\xxx yyy\gsview32.ini
[2013.01.20 16:40:09 | 000,698,314 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013.01.20 16:40:09 | 000,656,850 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.01.20 16:40:09 | 000,140,232 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013.01.20 16:40:09 | 000,121,446 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.01.08 23:33:23 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013.01.08 23:33:23 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
 
========== Files Created - No Company Name ==========
 
[2013.01.26 22:10:24 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.01.23 16:08:02 | 000,000,913 | ---- | C] () -- C:\Users\xxx yyy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
[2012.07.26 04:39:03 | 000,032,339 | ---- | C] () -- C:\Users\xxx yyy\.recently-used.xbel
[2011.09.27 17:59:06 | 000,098,304 | ---- | C] () -- C:\Windows\System32\redmonnt.dll
[2011.09.27 17:41:28 | 000,000,252 | ---- | C] () -- C:\Users\xxx yyy\.gtk-bookmarks
[2011.09.15 13:28:50 | 000,011,430 | ---- | C] () -- C:\Users\xxx yyy\gsview32.ini
[2011.09.10 18:54:57 | 000,007,301 | ---- | C] () -- C:\Users\xxx yyy\README
[2011.08.19 15:57:48 | 000,008,733 | ---- | C] () -- C:\Users\xxx yyy\_setup.xml
[2011.08.19 15:40:22 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011.08.19 15:40:22 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011.08.12 11:20:14 | 000,015,896 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2011.08.09 06:21:07 | 000,020,768 | ---- | C] () -- C:\Users\xxx yyy\#6.synctex.gz
[2011.08.09 04:07:46 | 000,000,000 | ---- | C] () -- C:\Users\xxx yyy\#6.lof
[2011.08.09 03:46:15 | 000,001,740 | ---- | C] () -- C:\Users\xxx yyy\#6.dvi
[2011.08.09 02:58:40 | 000,139,237 | ---- | C] () -- C:\Users\xxx yyy\#6.pdf
[2011.08.09 02:58:40 | 000,001,025 | ---- | C] () -- C:\Users\xxx yyy\#6.aux
[2011.08.09 02:58:40 | 000,000,818 | ---- | C] () -- C:\Users\xxx yyy\#6.toc
[2011.08.09 02:58:39 | 000,004,989 | ---- | C] () -- C:\Users\xxx yyy\#6.tex
[2011.08.09 01:23:55 | 000,035,143 | ---- | C] () -- C:\Users\xxx yyy\#1.pdf
[2011.08.09 01:23:55 | 000,000,623 | ---- | C] () -- C:\Users\xxx yyy\#1.synctex.gz
[2011.08.09 01:23:55 | 000,000,009 | ---- | C] () -- C:\Users\xxx yyy\#1.aux
[2011.08.09 01:22:17 | 000,000,097 | ---- | C] () -- C:\Users\xxx yyy\#1.tex
[2008.09.09 00:19:24 | 000,046,592 | ---- | C] () -- C:\Users\xxx yyy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
 
========== ZeroAccess Check ==========
 
[2006.11.02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2008.11.06 13:57:06 | 011,315,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.03.03 05:16:12 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2006.11.02 10:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

und das zweite

Code:

OTL Extras logfile created on: 28.01.2013 20:45:49 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\xxx yyy\Downloads
Windows Vista Home Premium Edition  (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,00 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 57,58% Memory free
6,19 Gb Paging File | 4,45 Gb Available in Paging File | 71,85% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 144,09 Gb Total Space | 78,37 Gb Free Space | 54,39% Space Free | Partition Type: NTFS
Drive D: | 144,00 Gb Total Space | 128,76 Gb Free Space | 89,42% Space Free | Partition Type: NTFS
 
Computer Name: xxx-PC | User Name: xxx yyy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05ADAECC-4DF2-4688-8564-DCC27AC98668}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{060BB3E0-9AA2-4CAB-A410-B35AC6BF8728}" = rport=445 | protocol=6 | dir=out | app=system |
"{3FD29A54-82D5-49A8-932B-6B15E43BE169}" = rport=138 | protocol=17 | dir=out | app=system |
"{515083B1-9E7D-4FD0-B3DC-A53E1AB290D8}" = lport=138 | protocol=17 | dir=in | app=system |
"{54566C3E-989B-4C60-99BE-57DC087E8431}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6C325106-AE8A-4EF0-9859-95C377129C4D}" = lport=445 | protocol=6 | dir=in | app=system |
"{87417409-7967-4B32-9D1B-7A3EC4820673}" = lport=137 | protocol=17 | dir=in | app=system |
"{8E03E3CA-B265-428A-A1FA-9F356D6A7709}" = lport=139 | protocol=6 | dir=in | app=system |
"{901DF5EC-E47D-4C92-9997-E9F0B8D27FA4}" = lport=19376 | protocol=6 | dir=in | app=c:\program files\devolo\dlan\devolonetsvc.exe |
"{9FB24ED2-9C28-4FF5-9DE5-E2743F95E6C8}" = lport=19375 | protocol=17 | dir=in | app=c:\program files\devolo\dlan\devolonetsvc.exe |
"{B2A0E6DA-B5E5-4A57-AC32-C4DDAED8760C}" = rport=139 | protocol=6 | dir=out | app=system |
"{DB954418-4B14-4FBB-95DE-97F1C941BF85}" = rport=137 | protocol=17 | dir=out | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01D1E27D-5E8F-4CD6-87F3-DA8EEE3E2DA1}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{08BC2828-2E5B-4AB0-B8B5-8CEEB1F8172F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{2C4CC177-B2B7-49C7-B967-5EF1A5E30837}" = protocol=17 | dir=in | app=c:\users\xxx yyy\appdata\roaming\dropbox\bin\dropbox.exe |
"{3E1996BD-407E-4447-A653-4E8A02CF1F42}" = protocol=6 | dir=in | app=c:\users\xxx yyy\appdata\roaming\dropbox\bin\dropbox.exe |
"{4F7B9496-7B5D-4FA0-8A89-EF2BE5634990}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{582278F5-9303-4C5D-89E4-12DB5D21D31B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{77F8C253-E2CC-4B72-8332-58D28C4717BF}" = dir=in | app=c:\program files\cyberlink\powerdvd\powerdvd.exe |
"{7D9DFF2A-6F2F-472C-B4F3-4B6B9CCDC755}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A273A860-6A62-4E7A-A4F6-9BB1C6CC6667}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{C3BD8FAE-E180-4FE5-BFDA-12DF3AB417CA}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C71C3F43-441C-40FD-A365-45FFB28D9602}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DA706094-CBD3-4EB0-AB30-0619FB1A254D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{E03C02EE-ADCD-4805-B0E4-C37A125979A2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"TCP Query User{6C18CEC6-9F60-41EB-BE62-A7496E9909CF}C:\program files\rayv\rayv\rayv.exe" = protocol=6 | dir=in | app=c:\program files\rayv\rayv\rayv.exe |
"UDP Query User{BCF63442-81C3-45B0-8F79-8EB73C08C532}C:\program files\rayv\rayv\rayv.exe" = protocol=17 | dir=in | app=c:\program files\rayv\rayv\rayv.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Professional
"{00040407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2
"{00AF10C1-44BD-4862-9D7F-24E6BA3E87FD}" = imagine digital freedom - Samsung
"{028ED9C4-25EE-4DEE-9CF4-91034BC89B18}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = WIDCOMM Bluetooth Software 6.0.1.5000
"{04983D37-2202-4295-94A2-8B547C66133F}" = Atheros WLAN Client
"{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu
"{07629207-FAA0-4F1A-8092-BF5085BE511F}" = Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch)
"{0795AE80-E3AD-C109-D0ED-127454F7947D}" = CCC Help Czech
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC3
"{08B785C1-3893-4154-B53B-F5D341D0AAAA}" = Cisco Systems VPN Client 5.0.06.0110
"{09C07EA5-2B33-D6A8-82EE-96E2EFB50933}" = Catalyst Control Center Localization German
"{0BDD74BD-5919-45DC-8DBD-FD9A7FFBEE7D}" = Catalyst Control Center Localization Czech
"{0DA98A0B-E9AA-7D76-9FFB-09666B57B977}" = CCC Help Japanese
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation(R)Store
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{113784E4-001C-F3B0-BB12-30301C352D5A}" = CCC Help Chinese Standard
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution II
"{15343122-1A4C-84D1-F14C-19DAD9C3E170}" = Catalyst Control Center Localization Chinese Traditional
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"{1ABD9408-C1DC-EF1F-40E8-2D9A6531CDA3}" = ATI Catalyst Install Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{230441A3-AEFA-1008-6874-E00CCD863C1B}" = ccc-utility
"{2376F2D7-47F6-7D31-454C-50B3E7B04D79}" = CCC Help English
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java(TM) 6 Update 21
"{26E0A023-F45C-F529-D820-180FDAFA2CF5}" = Catalyst Control Center Localization French
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 6.012.00
"{32D6A58F-9659-446C-BBFC-E6F2B41F24DC}" = Samsung Magic Doctor
"{33286280-8617-11E1-8FF6-B8AC6F97B88E}" = Google Earth Plug-in
"{36BEAD11-8577-49AD-9250-E06A50AE87B0}" = Microsoft SOAP Toolkit 2.0 SP2
"{37395A9B-AC98-4DBC-83CF-49FDB211742B}" = Scientific Word 5.0
"{39B1744D-0561-20FD-10BC-462349B2CD17}" = Catalyst Control Center Core Implementation
"{3EA29C6A-F433-2CFA-9343-A30061A31D40}" = Catalyst Control Center Graphics Light
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{4818083E-ADDE-37BD-7C86-4B72C7D96692}" = CCC Help Greek
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C4B9522-FD03-D17C-1A00-8EBC02CA5AC2}" = CCC Help French
"{4cb9f93c-9edc-4be9-ae61-af128ddbecfa}" = Business Contact Manager für Outlook 2007 SP2
"{4E271D3B-6105-525A-885D-72330974AABF}" = Catalyst Control Center Localization Spanish
"{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{535D722D-3CD3-7B2B-0D2A-8205AB81702D}" = Catalyst Control Center Localization Italian
"{57EB87EF-23DF-4A76-9B90-FD7B53E1C6CE}" = Langenscheidt T1 7.0
"{583ACB37-3139-562A-6279-0158480F2277}" = Catalyst Control Center Localization Japanese
"{59C4B635-2E5A-1141-C0E5-004FC4D196F4}" = CCC Help Thai
"{5CE3E15C-6E1D-A3FE-2E35-F40E83DDF68D}" = CCC Help German
"{5F6A4850-DDBE-DA71-0B73-10170D2A4E55}" = Catalyst Control Center Localization Korean
"{60B08761-8B36-4C10-51DC-C68AEA125612}" = CCC Help Turkish
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{640BBCC1-792B-8FF8-D5FF-EA185F1352BA}" = CCC Help Hungarian
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"{6D69A81D-B087-BFB2-DD8C-EF5FF34FBEC1}" = Catalyst Control Center Localization Norwegian
"{6EDE839E-B81A-28F0-5A7D-51A7128A1FD5}" = Catalyst Control Center Localization Greek
"{6F730513-8688-4C3C-90A3-6B9792CE2EF3}" = Easy Battery Manager
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A51B09-E7D3-11DB-A386-005056C00008}" = Vimicro UVC Camera
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{72F32AF2-2FA3-E6A0-D3D5-047691462436}" = CCC Help Danish
"{733D4DE8-14B8-EF66-CE77-160C0EC92913}" = CCC Help Swedish
"{74641F41-CE39-EA12-CD69-6903FD17544C}" = Catalyst Control Center Localization Turkish
"{74D5CF76-2DA9-7105-0BCB-3ACE774F478A}" = CCC Help Polish
"{76C1FD00-E569-A09E-E128-87B81203F6AA}" = CCC Help Portuguese
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7FB12670-0F93-4E1E-B2F5-4F339199A03A}" = Microsoft SQL Server Native Client
"{80574E0C-36A8-7974-0460-8B93A96A601E}" = Catalyst Control Center Graphics Full New
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.2.0
"{81E677EB-392F-FC88-7498-9506248689B4}" = CCC Help Italian
"{82310404-A89C-D870-769F-005031AFFD9B}" = CCC Help Spanish
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{846E4C72-DF45-43ED-1680-EDF5F87F279E}" = dLAN Cockpit
"{849A32C3-E75A-4791-9B11-E568BA3525A4}" = Microsoft SQL Server VSS Writer
"{861CD9E0-D0CE-00DA-20F7-DA8869E0954E}" = Catalyst Control Center Graphics Full Existing
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{8B14B6B8-342F-9556-46CA-D948734245D6}" = Catalyst Control Center Localization Dutch
"{8BF358A1-F53D-FF72-C844-FC4A4CE79B97}" = Catalyst Control Center Localization Hungarian
"{90120000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2007
"{90120000-0015-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2007
"{90120000-0019-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2007
"{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_PROHYBRIDR_{DB2ACBD1-65B1-4FC5-881E-4E75C668E7E2}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROHYBRIDR_{928D7B99-2BEA-49F9-83B8-20FA57860643}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROHYBRIDR_{A23BFC95-4A73-410F-9248-4C2B48E38C49}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_PROHYBRIDR_{A6353E8F-5B8D-47CC-8737-DFF032ED3973}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90A40407-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92C8DAA6-A0FA-DBDE-0464-5BEFAB4AB1B4}" = Catalyst Control Center Localization Chinese Standard
"{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"{997AEC5C-8E66-48A9-5149-E3E03F05710C}" = CCC Help Korean
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.4) - Deutsch
"{AD4CEE8C-0AF0-B4B2-D64B-7CCF70BD60B6}" = Catalyst Control Center Localization Russian
"{AE5906D7-1980-EA3B-711E-4BA92F0B70AA}" = Catalyst Control Center Localization Swedish
"{AF2F91EE-EF88-DB9A-5A0F-6E8B8C8901EA}" = Catalyst Control Center Localization Thai
"{AF97A9E8-155E-25C3-AAC2-377E3C2F8CE1}" = CCC Help Dutch
"{B161098B-279B-399C-63AC-68D1AECA98B8}" = CCC Help Chinese Traditional
"{B395BC1D-CC06-425E-9049-4CD985EFF004}" = LightScribe  1.8.15.1
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation(R)Network Downloader
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BE52510A-0CC8-EB71-9405-07E2B369526E}" = Catalyst Control Center Localization Portuguese
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint 2.0
"{C8167567-C053-7355-A2DE-DFD50B5E9F90}" = CCC Help Russian
"{C93F1C40-29E8-1351-3CAB-35DBBA6843F3}" = CCC Help Finnish
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E0363-B20C-4792-8A1C-8DF5E01B68A6}" = GoGear VIBE Device Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam-Software
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DDC49762-9664-28B4-97F3-24DA91618CBC}" = CCC Help Norwegian
"{DF85F51D-6908-5B09-FA13-5B3376C640E1}" = Skins
"{E380FD9E-D9AD-A7FF-2986-6A906836D79E}" = Catalyst Control Center Graphics Previews Vista
"{E63BD217-4154-3693-595B-0A6F38C611C1}" = Catalyst Control Center Localization Danish
"{E9EFEA79-C84D-45BA-7037-4DC356790BF8}" = ccc-core-static
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 1.60.13
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FA340E1B-0840-8F61-32CF-7A5A99A2C854}" = Catalyst Control Center Localization Polish
"{FBE5AA96-22F0-4C4A-8E92-4BE3498D4CCB}" = Media Go
"{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FE6D4D2B-154C-1485-81B8-D2F6F5C5CF30}" = Catalyst Control Center Localization Finnish
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Business Contact Manager" = Business Contact Manager für Outlook 2007 SP2
"Cockpit.92121A72F826FA9D0BD3A830E7F04987B31AFB22.1" = dLAN Cockpit
"conduitEngine" = Conduit Engine
"dlancockpit" = devolo dLAN Cockpit
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Evil Client" = Evil Client
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"GPL Ghostscript 9.04" = GPL Ghostscript
"GSview 4.9" = GSview 4.9
"InstallShield_{4EA8EA5D-8E46-4698-9BF7-2F2AD8E1C185}" = Easy Network Manager 3.0
"InstallShield_{685707A4-911C-468D-BFC4-64A50E5E3A0C}" = Samsung Update Plus
"InstallShield_{955597D8-E5E1-474D-B647-60AC44566D24}" = Play AVStation
"InstallShield_{FD53302C-8E7B-4730-8AD8-86A889BDBFAB}" = AVStation Now
"InstallWIX_{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.70.0.1100
"Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"MiKTeX 2.9" = MiKTeX 2.9
"Mozilla Firefox 15.0 (x86 de)" = Mozilla Firefox 15.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"PROHYBRIDR" = 2007 Microsoft Office system
"RayV" = RayV
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TexMakerX_is1" = TexMakerX 2.1
"TeXnicCenter_is1" = TeXnicCenter Version 1.0 Stable RC1
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.5
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinRAR archiver" = WinRAR
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-405802704-1985627685-3967156141-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 16.04.2012 16:01:26 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.04.2012 16:01:26 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9578
 
Error - 16.04.2012 16:01:26 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9578
 
Error - 16.04.2012 16:01:28 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.04.2012 16:01:28 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 10623
 
Error - 16.04.2012 16:01:28 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 10623
 
Error - 16.04.2012 16:01:29 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 16.04.2012 16:01:29 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 11653
 
Error - 16.04.2012 16:01:29 | Computer Name = xxx-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11653
 
Error - 17.04.2012 06:50:55 | Computer Name = xxx-PC | Source = EventSystem | ID = 4621
Description =
 
[ OSession Events ]
Error - 04.02.2011 08:29:29 | Computer Name = xxx-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 40 seconds with 0 seconds of active time.  This session ended with a crash.
 
[ System Events ]
Error - 27.01.2013 21:48:06 | Computer Name = xxx-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 7, Funktion 0.  Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 27.01.2013 21:48:23 | Computer Name = xxx-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
 
Error - 27.01.2013 21:50:05 | Computer Name = xxx-PC | Source = Service Control Manager | ID = 7000
Description =
 
Error - 27.01.2013 22:10:10 | Computer Name = xxx-PC | Source = DCOM | ID = 10010
Description =
 
Error - 28.01.2013 14:01:11 | Computer Name = xxx-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 2, Funktion 0.  Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 28.01.2013 14:01:11 | Computer Name = xxx-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 5, Funktion 0.  Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 28.01.2013 14:01:11 | Computer Name = xxx-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 6, Funktion 0.  Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 28.01.2013 14:01:12 | Computer Name = xxx-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI-BIOS enthält keinen IRQ für das Gerät im PCI-Steckplatz
 7, Funktion 0.  Wenden Sie sich an den Systemhersteller, um technische Unterstützung
 zu erhalten.
 
Error - 28.01.2013 14:01:29 | Computer Name = xxx-PC | Source = atikmdag | ID = 43034
Description = Unknown EDID version
 
Error - 28.01.2013 14:03:14 | Computer Name = xxx-PC | Source = Service Control Manager | ID = 7000
Description =
 
 
< End of report >

So das sind die beiden Log Files. Was mir aufgefallen ist, ist das heute um ca 14 Uhr irgendwas an meinem Laptop passiert ist. Zu dieser Zeit war ich aber nicht zu Hause und der Laptop war aus. :eek: Ich weiß nur leider nicht, was das zu bedeuten hat. Oder kann es einfach sein, dass mein Laptop eine andere Uhrzeit eingestellt hat. Die Uhrzeit die er mir auf dem Desktop anzeigt ist aber die normale Uhrzeit.
Liebe Grüße

P.S. noch eine kleine Ergänzung: Wahrscheinlich ist es total unwichtig, aber ich schreib es trotzdem mal. Nicht, dass ich was falsch gemacht habe: In der Anleitung steht, dass Vista Nutzer OTL mit Rechtsklick als Administrator starten sollen. Das hatte ich nicht zur Auswahl. Dafür hat ein Doppelklick wie für alle anderen Windows Versionen vorgegeben funktioniert.

cosinus 29.01.2013 12:16

Malwarebytes Anti-Rootkit http://img.trojaner-board.de/malware...otkit/logo.png

Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Entpacke das Archiv auf deinem Desktop.
  • Im neu erstellten Ordner starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Sophie_S. 29.01.2013 15:53

Hi, ich wollte gerade die mbar.exe starten. Leider habe ich eine Fehlermeldung bekommen, nachdem ich die Ausführung zugelassen habe:
Probable Rootkit activity detected
Registry Value "AppInit_Dlls", which may be caused by Rootkit activity.
Note: Press "No" Button if you're not sure. If the tool crashes or terminates unexpectedly during a system scan, restart the tool and press "Yes" should tis message appear again.

Do you want to remove this value and restart the tool?
:confused:
Ich hab leider keine Ahnung, was ich hier drücken soll. Wäre total lieb, wenn du mir das noch sagen könntest. :dankeschoen:
Lg Sophie

cosinus 29.01.2013 15:57

Drücke bitte auf NEIN - sowie es da steht, wenn man sich unsicher sein sollte immer NEIN drücken!

Sophie_S. 29.01.2013 16:05

Ok hab nein gedrückt. Leider habe ich sofort danach diese Meldung erhalten:
Your Version has been expired
Your Version of Malwarebytes Anti-Rootkit BETA has been outdated. Please download a newer Verision here: Malwarebytes : Malwarebytes Anti-Rootkit
Would you like to download a newer Version now?

Ich hab das Programm allerdings genau nach Anweisung auf der von euch angegebenen Seite heruntergeladen. Soll ich es einfach nochmal probieren?
Ich muss jetzt leider nochmal kurz in eine Vorlesung gehen und mache dann heute Abend weiter. Viele Dank nochmal für deine Hilfe. Finde ich echt super!!

cosinus 29.01.2013 16:09

http://downloads.malwarebytes.org/file/mbar

Sophie_S. 29.01.2013 20:18

Hallo Cosinus,
danke erstmal für das Programm. Es hat nichts gefunden und ein clean up war daher nicht nötig.
Hier das Log File
Code:

Malwarebytes Anti-Rootkit BETA 1.01.0.1017
www.malwarebytes.org

Database version: v2013.01.29.08

Windows Vista x86 NTFS
Internet Explorer 8.0.6001.18904
xxx yyy :: xxx-PC [administrator]

29.01.2013 19:53:41
mbar-log-2013-01-29 (19-53-41).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 30293
Time elapsed: 40 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Heißt das jetzt, dass mein Computer clean ist?
Viele Grüße und einen schönen Feierabend noch
Sophie

cosinus 29.01.2013 21:10

1. aswMBR

Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.

Hinweis: Bitte den Virenscanner abstellen bevor du aswMBR ausführst, denn v.a. Avira meldet darin oft einen Fehlalarm!
  • Starte die aswMBR.exe Vista und Win7 User aswMBR per Rechtsklick "als Administrator ausführen"
  • Das Tool wird dich fragen, ob Du mit der aktuellen Virendefinition von AVAST! dein System scannen willst. Beantworte diese Frage bitte mit Ja. (Sollte deine Firewall fragen, bitte den Zugriff auf das Internet zulassen) Der Download der Definitionen kann je nach Verbindung eine Weile dauern.
  • Klicke auf Scan.
  • Warte bitte bis Scan finished successfully im DOS Fenster steht.
  • Drücke auf Save Log und speichere diese auf dem Desktop.
Poste mir die aswMBR.txt in deiner nächsten Antwort. Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte es erneut nicht klappen teile mir das bitte mit.

Noch ein Hinweis: Sollte aswMBR abstürzen und es kommt eine Meldung wie "aswMBR.exe funktioniert nicht mehr, dann mach Folgendes:
Starte aswMBR neu, wähle unten links im Drop-Down-Menü (unten links im Fenster von aswMBR) bei "AV scan" (none) aus und klick nochmal auf den Scan-Button.


2. TDSS-Killer

Download TDSS-Killer auf Desktop siehe => http://www.trojaner-board.de/82358-t...entfernen.html

Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm!

Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet,
Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten.

Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition ( meistens Laufwerk C: ) nach, da speichert der TDSS-Killer seine Logs.

Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten!

http://saved.im/mtg4nzy0ywy5/settings_2012-09-04.png

Sophie_S. 29.01.2013 21:51

Hey noch eine mal wieder ganz dumme Frage meinerseits. Ich soll den Virenscanner abstellen, den ich generell verwende und nicht den der neuen Programme, die du mir gegeben hast, oder? :confused:

cosinus 29.01.2013 22:02

Es sollten jegliche im Hintergrund laufende Wächter abgestellt werden

Sophie_S. 04.02.2013 00:44

Hallo Cosinus,
tut mir Leid, dass ich mich so lange nicht gemeldet habe. War leider krank. So jetzt die beiden neuen Logfiles:
Code:

aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-04 00:23:44
-----------------------------
00:23:44.044    OS Version: Windows 6.0.6000
00:23:44.045    Number of processors: 2 586 0xF0D
00:23:44.053    ComputerName: xxx-PC  UserName:
00:23:47.004    Initialize success
00:26:02.946    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
00:26:02.951    Disk 0 Vendor: WDC_WD3200BEVT-22ZCT0 11.01A11 Size: 305245MB BusType: 3
00:26:03.052    Disk 0 MBR read successfully
00:26:03.056    Disk 0 MBR scan
00:26:03.059    Disk 0 unknown MBR code
00:26:03.117    Disk 0 Partition 1 00    27 Hidden NTFS WinRE NTFS        10240 MB offset 2048
00:26:03.206    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS      147548 MB offset 20973568
00:26:03.283    Disk 0 Partition 3 00    07    HPFS/NTFS NTFS      147455 MB offset 323151872
00:26:03.289    Disk 0 scanning sectors +625139712
00:26:03.369    Disk 0 scanning C:\Windows\system32\drivers
00:26:10.766    Service scanning
00:26:28.778    Modules scanning
00:26:39.795    Disk 0 trace - called modules:
00:26:39.844    ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys tcpip.sys NETIO.SYS
00:26:39.847    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d2f358]
00:26:39.848    3 ntoskrnl.exe[840a81bf] -> nt!IofCallDriver -> [0x86c168e8]
00:26:39.849    5 acpi.sys[8047632a] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85e8ebb0]
00:26:39.850    Scan finished successfully
00:27:11.624    Disk 0 MBR has been saved successfully to "C:\Users\xxx yyy\Desktop\MBR.dat"
00:27:11.654    The log file has been saved successfully to "C:\Users\xxx yyy\Desktop\aswMBR.txt"

und das zweite:
Code:

00:33:25.0376 1180  TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
00:33:26.0367 1180  ============================================================
00:33:26.0367 1180  Current date / time: 2013/02/04 00:33:26.0367
00:33:26.0367 1180  SystemInfo:
00:33:26.0367 1180 
00:33:26.0367 1180  OS Version: 6.0.6000 ServicePack: 0.0
00:33:26.0367 1180  Product type: Workstation
00:33:26.0368 1180  ComputerName: xxx-PC
00:33:26.0368 1180  UserName: xxx yyy
00:33:26.0368 1180  Windows directory: C:\Windows
00:33:26.0368 1180  System windows directory: C:\Windows
00:33:26.0368 1180  Processor architecture: Intel x86
00:33:26.0368 1180  Number of processors: 2
00:33:26.0368 1180  Page size: 0x1000
00:33:26.0368 1180  Boot type: Normal boot
00:33:26.0368 1180  ============================================================
00:33:28.0295 1180  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:33:28.0299 1180  ============================================================
00:33:28.0299 1180  \Device\Harddisk0\DR0:
00:33:28.0300 1180  MBR partitions:
00:33:28.0300 1180  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x1202E000
00:33:28.0300 1180  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1342E800, BlocksNum 0x11FFF800
00:33:28.0300 1180  ============================================================
00:33:28.0328 1180  C: <-> \Device\Harddisk0\DR0\Partition1
00:33:28.0369 1180  D: <-> \Device\Harddisk0\DR0\Partition2
00:33:28.0370 1180  ============================================================
00:33:28.0370 1180  Initialize success
00:33:28.0370 1180  ============================================================
00:34:42.0050 5936  ============================================================
00:34:42.0050 5936  Scan started
00:34:42.0050 5936  Mode: Manual; SigCheck; TDLFS;
00:34:42.0050 5936  ============================================================
00:34:42.0616 5936  ================ Scan system memory ========================
00:34:42.0616 5936  System memory - ok
00:34:42.0617 5936  ================ Scan services =============================
00:34:42.0783 5936  [ 84FC6DF81212D16BE5C4F441682FECCC ] ACPI            C:\Windows\system32\drivers\acpi.sys
00:34:43.0030 5936  ACPI - ok
00:34:43.0184 5936  [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
00:34:43.0202 5936  AdobeARMservice - ok
00:34:43.0319 5936  [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:34:43.0345 5936  AdobeFlashPlayerUpdateSvc - ok
00:34:43.0420 5936  [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx        C:\Windows\system32\drivers\adp94xx.sys
00:34:43.0455 5936  adp94xx - ok
00:34:43.0509 5936  [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci        C:\Windows\system32\drivers\adpahci.sys
00:34:43.0534 5936  adpahci - ok
00:34:43.0575 5936  [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
00:34:43.0593 5936  adpu160m - ok
00:34:43.0624 5936  [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320        C:\Windows\system32\drivers\adpu320.sys
00:34:43.0646 5936  adpu320 - ok
00:34:43.0706 5936  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
00:34:43.0848 5936  AeLookupSvc - ok
00:34:43.0894 5936  [ 5D24CAF8EFD924A875698FF28384DB8B ] AFD            C:\Windows\system32\drivers\afd.sys
00:34:44.0001 5936  AFD - ok
00:34:44.0048 5936  [ 39E435C90C9C4F780FA0ED05CA3C3A1B ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe
00:34:44.0100 5936  AgereModemAudio - ok
00:34:44.0181 5936  [ CE91B158FA490CF4C4D487A4130F4660 ] AgereSoftModem  C:\Windows\system32\DRIVERS\AGRSM.sys
00:34:44.0257 5936  AgereSoftModem - ok
00:34:44.0302 5936  [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440          C:\Windows\system32\drivers\agp440.sys
00:34:44.0320 5936  agp440 - ok
00:34:44.0365 5936  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx        C:\Windows\system32\drivers\djsvs.sys
00:34:44.0383 5936  aic78xx - ok
00:34:44.0417 5936  [ E69FB0E3112C40FDC0EF7D21A52DC951 ] ALG            C:\Windows\System32\alg.exe
00:34:44.0478 5936  ALG - ok
00:34:44.0504 5936  [ 90395B64600EBB4552E26E178C94B2E4 ] aliide          C:\Windows\system32\drivers\aliide.sys
00:34:44.0521 5936  aliide - ok
00:34:44.0538 5936  [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
00:34:44.0557 5936  amdagp - ok
00:34:44.0572 5936  [ 0577DF1D323FE75A739C787893D300EA ] amdide          C:\Windows\system32\drivers\amdide.sys
00:34:44.0589 5936  amdide - ok
00:34:44.0606 5936  [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7          C:\Windows\system32\drivers\amdk7.sys
00:34:44.0712 5936  AmdK7 - ok
00:34:44.0737 5936  [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8          C:\Windows\system32\drivers\amdk8.sys
00:34:44.0824 5936  AmdK8 - ok
00:34:44.0895 5936  [ CFA455816879F06F1C4E5BBF9E8AEF7D ] Appinfo        C:\Windows\System32\appinfo.dll
00:34:44.0975 5936  Appinfo - ok
00:34:45.0062 5936  [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
00:34:45.0079 5936  Apple Mobile Device - ok
00:34:45.0116 5936  [ 5F673180268BB1FDB69C99B6619FE379 ] arc            C:\Windows\system32\drivers\arc.sys
00:34:45.0135 5936  arc - ok
00:34:45.0166 5936  [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
00:34:45.0183 5936  arcsas - ok
00:34:45.0217 5936  [ E86CF7CE67D5DE898F27EF884DC357D8 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
00:34:45.0299 5936  AsyncMac - ok
00:34:45.0322 5936  [ E03E8C99D15D0381E02743C36AFC7C6F ] atapi          C:\Windows\system32\drivers\atapi.sys
00:34:45.0339 5936  atapi - ok
00:34:45.0405 5936  [ 91E15B0A1D6F7B99ACE55D04C6D1544A ] athr            C:\Windows\system32\DRIVERS\athr.sys
00:34:45.0489 5936  athr - ok
00:34:45.0574 5936  [ D045C4FC41EFA6CE74D85CAB4DA75C1F ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe
00:34:45.0642 5936  Ati External Event Utility - ok
00:34:45.0749 5936  [ 5439B251AF73E7EFAE4B8771D7116159 ] atikmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
00:34:45.0936 5936  atikmdag - ok
00:34:45.0981 5936  [ 4AA1EB65481C392955939E735D27118B ] AtiPcie        C:\Windows\system32\DRIVERS\AtiPcie.sys
00:34:46.0016 5936  AtiPcie - ok
00:34:46.0085 5936  [ E760FC1BD68F7F6F1B17EB4E8D9480B0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
00:34:46.0190 5936  AudioEndpointBuilder - ok
00:34:46.0218 5936  [ E760FC1BD68F7F6F1B17EB4E8D9480B0 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
00:34:46.0294 5936  Audiosrv - ok
00:34:46.0399 5936  [ A2B790F9A751F24F17967F9A5574186D ] AVP            C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe
00:34:46.0478 5936  AVP - ok
00:34:46.0571 5936  [ 6163664C7E9CD110AF70180C126C3FDC ] BcmSqlStartupSvc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
00:34:46.0589 5936  BcmSqlStartupSvc - ok
00:34:46.0638 5936  [ AC3DD1708B22761EBD7CBE14DCC3B5D7 ] Beep            C:\Windows\system32\drivers\Beep.sys
00:34:46.0745 5936  Beep - ok
00:34:46.0814 5936  [ 98EBDFFB824A7C265337D68DD480E45C ] BFE            C:\Windows\System32\bfe.dll
00:34:46.0909 5936  BFE - ok
00:34:46.0984 5936  [ DA551697E34D2B9943C8B1C8EAFFE89A ] BITS            C:\Windows\System32\qmgr.dll
00:34:47.0045 5936  BITS - ok
00:34:47.0054 5936  blbdrive - ok
00:34:47.0135 5936  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
00:34:47.0184 5936  Bonjour Service - ok
00:34:47.0216 5936  [ 913CD06FBE9105CE6077E90FD4418561 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
00:34:47.0312 5936  bowser - ok
00:34:47.0364 5936  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
00:34:47.0431 5936  BrFiltLo - ok
00:34:47.0450 5936  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
00:34:47.0493 5936  BrFiltUp - ok
00:34:47.0537 5936  [ BEB6470532B7461D7BB426E3FACB424F ] Browser        C:\Windows\System32\browser.dll
00:34:47.0610 5936  Browser - ok
00:34:47.0654 5936  [ B304E75CFF293029EDDF094246747113 ] Brserid        C:\Windows\system32\drivers\brserid.sys
00:34:47.0735 5936  Brserid - ok
00:34:47.0754 5936  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
00:34:47.0837 5936  BrSerWdm - ok
00:34:47.0856 5936  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
00:34:47.0926 5936  BrUsbMdm - ok
00:34:47.0948 5936  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
00:34:48.0035 5936  BrUsbSer - ok
00:34:48.0085 5936  [ 064FBC56921051DE1075495D628B815F ] BthEnum        C:\Windows\system32\DRIVERS\BthEnum.sys
00:34:48.0117 5936  BthEnum - ok
00:34:48.0182 5936  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
00:34:48.0271 5936  BTHMODEM - ok
00:34:48.0328 5936  [ B8C3D9DDF85FD197C3E5F849FEF71144 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
00:34:48.0415 5936  BthPan - ok
00:34:48.0462 5936  [ B24757D9154CCA035E1BBD3DB92966D7 ] BTHPORT        C:\Windows\system32\Drivers\BTHport.sys
00:34:48.0498 5936  BTHPORT - ok
00:34:48.0537 5936  [ 58EE7F5E68310BC8D4E7CEBD8358C12E ] BthServ        C:\Windows\System32\bthserv.dll
00:34:48.0592 5936  BthServ - ok
00:34:48.0617 5936  [ D42CF5F0C7635B3F1578810FE34D9E41 ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
00:34:48.0654 5936  BTHUSB - ok
00:34:48.0701 5936  [ 636F45A8500C1438CFA7DEE15FC5C184 ] btwaudio        C:\Windows\system32\drivers\btwaudio.sys
00:34:48.0718 5936  btwaudio - ok
00:34:48.0753 5936  [ BF9256FF01B093A5D90BB7A35EC90410 ] btwavdt        C:\Windows\system32\drivers\btwavdt.sys
00:34:48.0769 5936  btwavdt - ok
00:34:48.0791 5936  [ 0AB8C1AC177AFB27309E1072FAF34A37 ] btwrchid        C:\Windows\system32\DRIVERS\btwrchid.sys
00:34:48.0805 5936  btwrchid - ok
00:34:48.0849 5936  [ 6C3A437FC873C6F6A4FC620B6888CB86 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
00:34:48.0940 5936  cdfs - ok
00:34:48.0979 5936  [ 8D1866E61AF096AE8B582454F5E4D303 ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
00:34:49.0051 5936  cdrom - ok
00:34:49.0094 5936  [ 0600E04315FE543802A379D5D23C8BE0 ] CertPropSvc    C:\Windows\System32\certprop.dll
00:34:49.0175 5936  CertPropSvc - ok
00:34:49.0204 5936  [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass        C:\Windows\system32\drivers\circlass.sys
00:34:49.0287 5936  circlass - ok
00:34:49.0310 5936  [ 1B84FD0937D3B99AF9BA38DDFF3DAF54 ] CLFS            C:\Windows\system32\CLFS.sys
00:34:49.0335 5936  CLFS - ok
00:34:49.0384 5936  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:34:49.0403 5936  clr_optimization_v2.0.50727_32 - ok
00:34:49.0464 5936  [ ED97AD3DF1B9005989EAF149BF06C821 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
00:34:49.0499 5936  CmBatt - ok
00:34:49.0515 5936  [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
00:34:49.0535 5936  cmdide - ok
00:34:49.0547 5936  [ 722936AFB75A7F509662B69B5632F48A ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
00:34:49.0568 5936  Compbatt - ok
00:34:49.0579 5936  COMSysApp - ok
00:34:49.0591 5936  [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk        C:\Windows\system32\drivers\crcdisk.sys
00:34:49.0614 5936  crcdisk - ok
00:34:49.0637 5936  [ 22A7F883508176489F559EE745B5BF5D ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
00:34:49.0723 5936  Crusoe - ok
00:34:49.0764 5936  [ 1C26FB097170A2A91066D1E3A24366E3 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
00:34:49.0846 5936  CryptSvc - ok
00:34:49.0906 5936  [ 5CBF20674BE8364FEBB6A13451A42F0A ] CSCrySec        C:\Windows\system32\DRIVERS\CSCrySec.sys
00:34:49.0946 5936  CSCrySec - ok
00:34:50.0083 5936  [ 6E5B42219F1FE4A3D087D9D501E343D5 ] CSObjectsSrv    C:\Program Files\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
00:34:50.0135 5936  CSObjectsSrv - ok
00:34:50.0178 5936  [ 2C3F213EDDD231099FB779A45D7680E0 ] CSVirtualDiskDrv C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys
00:34:50.0195 5936  CSVirtualDiskDrv - ok
00:34:50.0244 5936  [ B5ECADF7708960F1818C7FA015F4C239 ] CVirtA          C:\Windows\system32\DRIVERS\CVirtA.sys
00:34:50.0284 5936  CVirtA - ok
00:34:50.0401 5936  [ EA4300E53E5D4D1912AD04985F6264F0 ] CVPND          C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
00:34:50.0525 5936  CVPND - ok
00:34:50.0587 5936  [ 34C345AAF390C12AE6E51B75198E8564 ] CVPNDRVA        C:\Windows\system32\Drivers\CVPNDRVA.sys
00:34:50.0607 5936  CVPNDRVA ( UnsignedFile.Multi.Generic ) - warning
00:34:50.0607 5936  CVPNDRVA - detected UnsignedFile.Multi.Generic (1)
00:34:50.0684 5936  [ 7B981222A257D076885BFFB66F19B7CE ] DcomLaunch      C:\Windows\system32\rpcss.dll
00:34:50.0769 5936  DcomLaunch - ok
00:34:50.0945 5936  [ D17845A5385BFCB838CDC532AF5E3E47 ] DevoloNetworkService C:\Program Files\devolo\dlan\devolonetsvc.exe
00:34:51.0123 5936  DevoloNetworkService - ok
00:34:51.0163 5936  [ A7179DE59AE269AB70345527894CCD7C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
00:34:51.0261 5936  DfsC - ok
00:34:51.0378 5936  [ E0D584AA76C7D845BA9F3A788260528F ] DFSR            C:\Windows\system32\DFSR.exe
00:34:51.0652 5936  DFSR - ok
00:34:51.0727 5936  [ DC45739BC22D528D2B3E50D3F6761750 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
00:34:51.0785 5936  Dhcp - ok
00:34:51.0847 5936  [ 841AF4C4D41D3E3B2F244E976B0F7963 ] disk            C:\Windows\system32\drivers\disk.sys
00:34:51.0869 5936  disk - ok
00:34:51.0925 5936  [ B5AA5AA5AC327BD7C1AEC0C58F0C1144 ] DNE            C:\Windows\system32\DRIVERS\dne2000.sys
00:34:51.0946 5936  DNE - ok
00:34:51.0966 5936  [ EECBA1DD142BF8693C476BE8F32FE253 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
00:34:52.0030 5936  Dnscache - ok
00:34:52.0057 5936  [ 1F795D214820E496BF1124434A6DB546 ] dot3svc        C:\Windows\System32\dot3svc.dll
00:34:52.0169 5936  dot3svc - ok
00:34:52.0209 5936  [ 032C90AD677BF7B7A8013D6087C7A921 ] DPS            C:\Windows\system32\dps.dll
00:34:52.0267 5936  DPS - ok
00:34:52.0306 5936  [ EE472CD2C01F6F8E8AA1FA06FFEF61B6 ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
00:34:52.0406 5936  drmkaud - ok
00:34:52.0450 5936  [ 334988883DE69ADB27E2CF9F9715BBDB ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
00:34:52.0526 5936  DXGKrnl - ok
00:34:52.0571 5936  [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60          C:\Windows\system32\DRIVERS\E1G60I32.sys
00:34:52.0657 5936  E1G60 - ok
00:34:52.0699 5936  [ 90A0A875642E18618010645311B4E89E ] EapHost        C:\Windows\System32\eapsvc.dll
00:34:52.0784 5936  EapHost - ok
00:34:52.0828 5936  [ 0EFC7531B936EE57FDB4E837664C509F ] Ecache          C:\Windows\system32\drivers\ecache.sys
00:34:52.0847 5936  Ecache - ok
00:34:52.0911 5936  [ 792F72E8B63DF55CE98445D464874986 ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
00:34:52.0949 5936  ehRecvr - ok
00:34:52.0981 5936  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched        C:\Windows\ehome\ehsched.exe
00:34:53.0038 5936  ehSched - ok
00:34:53.0059 5936  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart        C:\Windows\ehome\ehstart.dll
00:34:53.0082 5936  ehstart - ok
00:34:53.0110 5936  [ E8F3F21A71720C84BCF423B80028359F ] elxstor        C:\Windows\system32\drivers\elxstor.sys
00:34:53.0137 5936  elxstor - ok
00:34:53.0201 5936  [ 3226FDA08988526E819E364E8CCE4CEE ] EMDMgmt        C:\Windows\system32\emdmgmt.dll
00:34:53.0239 5936  EMDMgmt - ok
00:34:53.0285 5936  [ 7B4971C3D43525175A4EA0D143E0412E ] EventSystem    C:\Windows\system32\es.dll
00:34:53.0328 5936  EventSystem - ok
00:34:53.0361 5936  [ 84A317CB0B3954D3768CDCD018DBF670 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
00:34:53.0441 5936  fastfat - ok
00:34:53.0475 5936  [ 63BDADA84951B9C03E641800E176898A ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
00:34:53.0561 5936  fdc - ok
00:34:53.0582 5936  [ E43BCE1A77D6FD4ED5F8E0482B9E7DF1 ] fdPHost        C:\Windows\system32\fdPHost.dll
00:34:53.0672 5936  fdPHost - ok
00:34:53.0701 5936  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
00:34:53.0788 5936  FDResPub - ok
00:34:53.0822 5936  [ 65773D6115C037FFD7EF8280AE85EB9D ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
00:34:53.0840 5936  FileInfo - ok
00:34:53.0871 5936  [ C226DD0DE060745F3E042F58DCF78402 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
00:34:53.0957 5936  Filetrace - ok
00:34:53.0983 5936  [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
00:34:54.0071 5936  flpydisk - ok
00:34:54.0102 5936  [ A6A8DA7AE4D53394AB22AC3AB6D3F5D3 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
00:34:54.0129 5936  FltMgr - ok
00:34:54.0177 5936  [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
00:34:54.0197 5936  FontCache3.0.0.0 - ok
00:34:54.0212 5936  [ 66A078591208BAA210C7634B11EB392C ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
00:34:54.0260 5936  Fs_Rec - ok
00:34:54.0278 5936  [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
00:34:54.0300 5936  gagp30kx - ok
00:34:54.0345 5936  [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM    C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:34:54.0359 5936  GEARAspiWDM - ok
00:34:54.0417 5936  [ BCF6589C42D8F6A20F33EF133FFE0524 ] gpsvc          C:\Windows\System32\gpsvc.dll
00:34:54.0516 5936  gpsvc - ok
00:34:54.0584 5936  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate        C:\Program Files\Google\Update\GoogleUpdate.exe
00:34:54.0601 5936  gupdate - ok
00:34:54.0628 5936  [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
00:34:54.0645 5936  gupdatem - ok
00:34:54.0680 5936  [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
00:34:54.0771 5936  HdAudAddService - ok
00:34:54.0795 5936  [ 0DB613A7E427B5663563677796FD5258 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
00:34:54.0829 5936  HDAudBus - ok
00:34:54.0845 5936  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
00:34:54.0929 5936  HidBth - ok
00:34:54.0952 5936  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr          C:\Windows\system32\drivers\hidir.sys
00:34:55.0033 5936  HidIr - ok
00:34:55.0069 5936  [ 8FA640195279ACE21BEA91396A0054FC ] hidserv        C:\Windows\system32\hidserv.dll
00:34:55.0155 5936  hidserv - ok
00:34:55.0192 5936  [ 01E7971E9F4BD6AC6A08DB52D0EA0418 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
00:34:55.0295 5936  HidUsb - ok
00:34:55.0343 5936  [ D40AA05E29BF6ED29B139F044B461E9B ] hkmsvc          C:\Windows\system32\kmsvc.dll
00:34:55.0434 5936  hkmsvc - ok
00:34:55.0454 5936  [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs        C:\Windows\system32\drivers\hpcisss.sys
00:34:55.0475 5936  HpCISSs - ok
00:34:55.0526 5936  [ EA24FE637D974A8A31BC650F478E3533 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
00:34:55.0610 5936  HTTP - ok
00:34:55.0629 5936  [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp          C:\Windows\system32\drivers\i2omp.sys
00:34:55.0650 5936  i2omp - ok
00:34:55.0701 5936  [ 1C9EE072BAA3ABB460B91D7EE9152660 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
00:34:55.0741 5936  i8042prt - ok
00:34:55.0779 5936  [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV        C:\Windows\system32\drivers\iastorv.sys
00:34:55.0806 5936  iaStorV - ok
00:34:55.0894 5936  [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:34:55.0975 5936  idsvc - ok
00:34:56.0000 5936  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp          C:\Windows\system32\drivers\iirsp.sys
00:34:56.0018 5936  iirsp - ok
00:34:56.0068 5936  [ 35662FE4D8622F667AA5A5568F7F1B40 ] IKEEXT          C:\Windows\System32\ikeext.dll
00:34:56.0178 5936  IKEEXT - ok
00:34:56.0279 5936  [ 7BD4E0428776D11C8E8E26F9F5508690 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
00:34:56.0481 5936  IntcAzAudAddService - ok
00:34:56.0503 5936  [ 97469037714070E45194ED318D636401 ] intelide        C:\Windows\system32\drivers\intelide.sys
00:34:56.0524 5936  intelide - ok
00:34:56.0557 5936  [ CE44CC04262F28216DD4341E9E36A16F ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
00:34:56.0659 5936  intelppm - ok
00:34:56.0681 5936  [ 88CF5281ED9880D74DC9011CF8B5262D ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
00:34:56.0785 5936  IPBusEnum - ok
00:34:56.0836 5936  [ 880C6F86CC3F551B8FEA2C11141268C0 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:34:56.0941 5936  IpFilterDriver - ok
00:34:56.0967 5936  [ ECC9AD72CFC4AB41CF6A9BCC11F9FEF6 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
00:34:57.0037 5936  iphlpsvc - ok
00:34:57.0046 5936  IpInIp - ok
00:34:57.0083 5936  [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV        C:\Windows\system32\drivers\ipmidrv.sys
00:34:57.0180 5936  IPMIDRV - ok
00:34:57.0212 5936  [ 10077C35845101548037DF04FD1A420B ] IPNAT          C:\Windows\system32\DRIVERS\ipnat.sys
00:34:57.0302 5936  IPNAT - ok
00:34:57.0378 5936  [ BC0EA61246F8D940FBC5F652D337D6BD ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
00:34:57.0427 5936  iPod Service - ok
00:34:57.0454 5936  [ A82F328F4792304184642D6D397BB1E3 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
00:34:57.0539 5936  IRENUM - ok
00:34:57.0561 5936  [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
00:34:57.0579 5936  isapnp - ok
00:34:57.0597 5936  [ 4DCA456D4D5723F8FA9C6760D240B0DF ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
00:34:57.0619 5936  iScsiPrt - ok
00:34:57.0641 5936  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
00:34:57.0658 5936  iteatapi - ok
00:34:57.0692 5936  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid        C:\Windows\system32\drivers\iteraid.sys
00:34:57.0712 5936  iteraid - ok
00:34:57.0735 5936  [ B076B2AB806B3F696DAB21375389101C ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
00:34:57.0752 5936  kbdclass - ok
00:34:57.0773 5936  [ D2600CB17B7408B4A83F231DC9A11AC3 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
00:34:57.0852 5936  kbdhid - ok
00:34:57.0886 5936  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] KeyIso          C:\Windows\system32\lsass.exe
00:34:57.0939 5936  KeyIso - ok
00:34:57.0977 5936  [ CE3958F58547454884E97BDA78CD7040 ] kl1            C:\Windows\system32\DRIVERS\kl1.sys
00:34:57.0995 5936  kl1 - ok
00:34:58.0012 5936  [ 53EEDAB3F0511321AC3AE8BC968B158C ] KLBG            C:\Windows\system32\DRIVERS\klbg.sys
00:34:58.0029 5936  KLBG - ok
00:34:58.0108 5936  [ 723F185C945C0A6D2E21C2BB26A46FE7 ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
00:34:58.0130 5936  KLIF - ok
00:34:58.0156 5936  [ 892CC162DC88AB084C86485879526C59 ] KLIM6          C:\Windows\system32\DRIVERS\klim6.sys
00:34:58.0171 5936  KLIM6 - ok
00:34:58.0196 5936  [ AA63A815876A76987B5DBCE6AF7478E9 ] klmouflt        C:\Windows\system32\DRIVERS\klmouflt.sys
00:34:58.0210 5936  klmouflt - ok
00:34:58.0244 5936  [ EBC507F129DF8F0E0CA270DCFC0CF87F ] KMDFMEMIO      C:\Windows\system32\DRIVERS\kmdfmemio.sys
00:34:58.0290 5936  KMDFMEMIO - ok
00:34:58.0350 5936  [ 0A829977B078DEA11641FC2AF87CEADE ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
00:34:58.0394 5936  KSecDD - ok
00:34:58.0457 5936  [ 45C537FE5DDE9A0146AEFF76E615737D ] KtmRm          C:\Windows\system32\msdtckrm.dll
00:34:58.0546 5936  KtmRm - ok
00:34:58.0591 5936  [ 53D1482FC1AA36AC015A85E6CF2146BD ] LanmanServer    C:\Windows\system32\srvsvc.dll
00:34:58.0676 5936  LanmanServer - ok
00:34:58.0717 5936  [ 435F0F6DC87A4B5DA78F1FA309884189 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
00:34:58.0770 5936  LanmanWorkstation - ok
00:34:58.0826 5936  [ F34B35F6F74E28A460749DA11D1117F8 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
00:34:58.0841 5936  LightScribeService - ok
00:34:58.0857 5936  [ FD015B4F95DAA2B712F0E372A116FBAD ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
00:34:58.0946 5936  lltdio - ok
00:34:58.0985 5936  [ 7450DBCF754391DD6363FFFD5EF0E789 ] lltdsvc        C:\Windows\System32\lltdsvc.dll
00:34:59.0075 5936  lltdsvc - ok
00:34:59.0111 5936  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts        C:\Windows\System32\lmhsvc.dll
00:34:59.0185 5936  lmhosts - ok
00:34:59.0231 5936  [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
00:34:59.0249 5936  LSI_FC - ok
00:34:59.0269 5936  [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS        C:\Windows\system32\drivers\lsi_sas.sys
00:34:59.0288 5936  LSI_SAS - ok
00:34:59.0322 5936  [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
00:34:59.0341 5936  LSI_SCSI - ok
00:34:59.0368 5936  [ 42885BB44B6E065B8575A8DD6C430C52 ] luafv          C:\Windows\system32\drivers\luafv.sys
00:34:59.0460 5936  luafv - ok
00:34:59.0510 5936  [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
00:34:59.0526 5936  MBAMProtector - ok
00:34:59.0608 5936  [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler  C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
00:34:59.0655 5936  MBAMScheduler - ok
00:34:59.0720 5936  [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
00:34:59.0753 5936  MBAMService - ok
00:34:59.0804 5936  [ E93C1AD58E88A0846EAEE10671C2A8F3 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
00:34:59.0844 5936  Mcx2Svc - ok
00:34:59.0896 5936  [ D153B14FC6598EAE8422A2037553ADCE ] megasas        C:\Windows\system32\drivers\megasas.sys
00:34:59.0913 5936  megasas - ok
00:34:59.0951 5936  [ 9DFA3A459AF0954AA85B4F7622AD87BB ] MMCSS          C:\Windows\system32\mmcss.dll
00:35:00.0050 5936  MMCSS - ok
00:35:00.0096 5936  [ 21755967298A46FB6ADFEC9DB6012211 ] Modem          C:\Windows\system32\drivers\modem.sys
00:35:00.0176 5936  Modem - ok
00:35:00.0210 5936  [ 7446E104A5FE5987CA9E4983FBAC4F97 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
00:35:00.0258 5936  monitor - ok
00:35:00.0285 5936  [ 5FBA13C1A1841B0885D316ED3589489D ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
00:35:00.0303 5936  mouclass - ok
00:35:00.0326 5936  [ A3A6DFF7E9E757DB3DF51A833BC28885 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
00:35:00.0443 5936  mouhid - ok
00:35:00.0463 5936  [ 01F1E5A3E4877C931CBB31613FEC16A6 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
00:35:00.0483 5936  MountMgr - ok
00:35:00.0542 5936  [ E8D79312373F254DC13F3965BDB3D521 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
00:35:00.0565 5936  MozillaMaintenance - ok
00:35:00.0611 5936  [ 583A41F26278D9E0EA548163D6139397 ] mpio            C:\Windows\system32\drivers\mpio.sys
00:35:00.0633 5936  mpio - ok
00:35:00.0659 5936  [ 6E7A7F0C1193EE5648443FE2D4B789EC ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
00:35:00.0720 5936  mpsdrv - ok
00:35:00.0766 5936  [ 563ED845885C6A7C09A7715D8BD0585C ] MpsSvc          C:\Windows\system32\mpssvc.dll
00:35:00.0827 5936  MpsSvc - ok
00:35:00.0843 5936  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
00:35:00.0860 5936  Mraid35x - ok
00:35:00.0890 5936  [ 1D8828B98EE309D65E006F0829E280E5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
00:35:00.0945 5936  MRxDAV - ok
00:35:00.0964 5936  [ 8AF705CE1BB907932157FAB821170F27 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
00:35:01.0001 5936  mrxsmb - ok
00:35:01.0026 5936  [ 47E13AB23371BE3279EEF22BBFA2C1BE ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:35:01.0067 5936  mrxsmb10 - ok
00:35:01.0090 5936  [ 90B3FC7BD6B3D7EE7635DEBBA2187F66 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:35:01.0131 5936  mrxsmb20 - ok
00:35:01.0152 5936  [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci          C:\Windows\system32\drivers\msahci.sys
00:35:01.0170 5936  msahci - ok
00:35:01.0191 5936  [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
00:35:01.0209 5936  msdsm - ok
00:35:01.0235 5936  [ BC64A92D821EFEA8BAB8E8CAF1B668BC ] MSDTC          C:\Windows\System32\msdtc.exe
00:35:01.0287 5936  MSDTC - ok
00:35:01.0313 5936  [ 729EAFEFD4E7417165F353A18DBE947D ] Msfs            C:\Windows\system32\drivers\Msfs.sys
00:35:01.0413 5936  Msfs - ok
00:35:01.0444 5936  [ 207DF26DBB2537C20276DA0E15892274 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
00:35:01.0461 5936  msisadrv - ok
00:35:01.0501 5936  [ 8ACF956D9154E893E789881430C12632 ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
00:35:01.0589 5936  MSiSCSI - ok
00:35:01.0596 5936  msiserver - ok
00:35:01.0629 5936  [ 892CEDEFA7E0FFE7BE8DA651B651D047 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
00:35:01.0705 5936  MSKSSRV - ok
00:35:01.0721 5936  [ AE2CB1DA69B2676B4CEE2A501AF5871C ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
00:35:01.0806 5936  MSPCLOCK - ok
00:35:01.0831 5936  [ F910DA84FA90C44A3ADDB7CD874463FD ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
00:35:01.0919 5936  MSPQM - ok
00:35:01.0945 5936  [ 84571C0AE07647BA38D493F5F0015DF7 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
00:35:01.0967 5936  MsRPC - ok
00:35:01.0987 5936  [ 7DBAA028F625AA46B95DDA4FBE4B602B ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
00:35:02.0004 5936  mssmbios - ok
00:35:02.0075 5936  MSSQL$MSSMLBIZ - ok
00:35:02.0114 5936  [ C06EA83F6FC2959E897C117255B6B1D5 ] MSSQLServerADHelper C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
00:35:02.0130 5936  MSSQLServerADHelper - ok
00:35:02.0146 5936  [ C826DD1373F38AFD9CA46EC3C436A14E ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
00:35:02.0237 5936  MSTEE - ok
00:35:02.0258 5936  [ FA7AA70050CF5E2D15DE00941E5665E5 ] Mup            C:\Windows\system32\Drivers\mup.sys
00:35:02.0276 5936  Mup - ok
00:35:02.0319 5936  [ 1CDBB5D002FE2BC5300AA20550D8A52E ] napagent        C:\Windows\system32\qagentRT.dll
00:35:02.0417 5936  napagent - ok
00:35:02.0468 5936  [ 6DA4A0FC7C0E83DF0CB3CFD0A514C3BC ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
00:35:02.0508 5936  NativeWifiP - ok
00:35:02.0552 5936  [ FFFE00134C554E113EE186EEDDB0FF30 ] NDIS            C:\Windows\system32\drivers\ndis.sys
00:35:02.0611 5936  NDIS - ok
00:35:02.0621 5936  [ 81659CDCBD0F9A9E07E6878AD8C78D3F ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
00:35:02.0673 5936  NdisTapi - ok
00:35:02.0695 5936  [ 5DE5EE546BF40838EBE0E01CB629DF64 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
00:35:02.0783 5936  Ndisuio - ok
00:35:02.0808 5936  [ 397402ADCBB8946223A1950101F6CD94 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
00:35:02.0889 5936  NdisWan - ok
00:35:02.0907 5936  [ 1B24FA907AF283199A81B3BB37E5E526 ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
00:35:02.0942 5936  NDProxy - ok
00:35:02.0962 5936  [ 356DBB9F98E8DC1028DD3092FCEEB877 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
00:35:03.0053 5936  NetBIOS - ok
00:35:03.0082 5936  [ E3A168912E7EEFC3BD3B814720D68B41 ] netbt          C:\Windows\system32\DRIVERS\netbt.sys
00:35:03.0176 5936  netbt - ok
00:35:03.0186 5936  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] Netlogon        C:\Windows\system32\lsass.exe
00:35:03.0212 5936  Netlogon - ok
00:35:03.0250 5936  [ 90A4DAE28B94497F83BEA0F2A3B77092 ] Netman          C:\Windows\System32\netman.dll
00:35:03.0338 5936  Netman - ok
00:35:03.0365 5936  [ 7C5C3D9CEEE838856B828AB6F98A2857 ] netprofm        C:\Windows\System32\netprofm.dll
00:35:03.0462 5936  netprofm - ok
00:35:03.0504 5936  [ 0AD5876EF4E9EB77C8F93EB5B2FFF386 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
00:35:03.0527 5936  NetTcpPortSharing - ok
00:35:03.0659 5936  [ 6E9EDC1020B319E7676387B8CDF2398C ] NETw2v32        C:\Windows\system32\DRIVERS\NETw2v32.sys
00:35:03.0925 5936  NETw2v32 - ok
00:35:04.0018 5936  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960        C:\Windows\system32\drivers\nfrd960.sys
00:35:04.0035 5936  nfrd960 - ok
00:35:04.0065 5936  [ C424117A562F2DE37A42266894C79AEB ] NlaSvc          C:\Windows\System32\nlasvc.dll
00:35:04.0143 5936  NlaSvc - ok
00:35:04.0183 5936  [ 4F9832BEB9FAFD8CEB0E541F1323B26E ] Npfs            C:\Windows\system32\drivers\Npfs.sys
00:35:04.0266 5936  Npfs - ok
00:35:04.0323 5936  [ 75AC610A7481CB1F343DC971249BCB19 ] NPF_devolo      C:\Windows\system32\drivers\npf_devolo.sys
00:35:04.0340 5936  NPF_devolo ( UnsignedFile.Multi.Generic ) - warning
00:35:04.0340 5936  NPF_devolo - detected UnsignedFile.Multi.Generic (1)
00:35:04.0383 5936  [ 23B8201A363DE0E649FC75EE9874DEE2 ] nsi            C:\Windows\system32\nsisvc.dll
00:35:04.0492 5936  nsi - ok
00:35:04.0520 5936  [ B488DFEC274DE1FC9D653870EF2587BE ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
00:35:04.0626 5936  nsiproxy - ok
00:35:04.0681 5936  [ 37430AA7A66D7A63407ADC2C0D05E9F6 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
00:35:04.0776 5936  Ntfs - ok
00:35:04.0809 5936  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi      C:\Windows\system32\drivers\ntrigdigi.sys
00:35:04.0915 5936  ntrigdigi - ok
00:35:04.0937 5936  [ EC5EFB3C60F1B624648344A328BCE596 ] Null            C:\Windows\system32\drivers\Null.sys
00:35:05.0024 5936  Null - ok
00:35:05.0052 5936  [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
00:35:05.0071 5936  nvraid - ok
00:35:05.0093 5936  [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor          C:\Windows\system32\drivers\nvstor.sys
00:35:05.0111 5936  nvstor - ok
00:35:05.0132 5936  [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
00:35:05.0152 5936  nv_agp - ok
00:35:05.0159 5936  NwlnkFlt - ok
00:35:05.0170 5936  NwlnkFwd - ok
00:35:05.0259 5936  [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
00:35:05.0293 5936  odserv - ok
00:35:05.0330 5936  [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
00:35:05.0437 5936  ohci1394 - ok
00:35:05.0578 5936  [ DA345DE3B450E9E1691E7B9956D8FFC3 ] OMSI download service C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
00:35:05.0623 5936  OMSI download service ( UnsignedFile.Multi.Generic ) - warning
00:35:05.0623 5936  OMSI download service - detected UnsignedFile.Multi.Generic (1)
00:35:05.0708 5936  [ 5A432A042DAE460ABE7199B758E8606C ] ose            C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:35:05.0734 5936  ose - ok
00:35:05.0796 5936  [ 016D01D3B8FB976A193C7434BED8DCCF ] p2pimsvc        C:\Windows\system32\p2psvc.dll
00:35:05.0890 5936  p2pimsvc - ok
00:35:05.0929 5936  [ 016D01D3B8FB976A193C7434BED8DCCF ] p2psvc          C:\Windows\system32\p2psvc.dll
00:35:06.0004 5936  p2psvc - ok
00:35:06.0038 5936  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport        C:\Windows\system32\drivers\parport.sys
00:35:06.0154 5936  Parport - ok
00:35:06.0195 5936  [ 555A5B2C8022983BC7467BC925B222EE ] partmgr        C:\Windows\system32\drivers\partmgr.sys
00:35:06.0224 5936  partmgr - ok
00:35:06.0251 5936  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
00:35:06.0351 5936  Parvdm - ok
00:35:06.0374 5936  [ D8C5C215C932233A4F1D7F368F4E4E65 ] PcaSvc          C:\Windows\System32\pcasvc.dll
00:35:06.0402 5936  PcaSvc - ok
00:35:06.0425 5936  [ BDD96F9CF34D58958AFF1BE6EF4C8020 ] pci            C:\Windows\system32\drivers\pci.sys
00:35:06.0445 5936  pci - ok
00:35:06.0484 5936  [ B2FC76090EF1003463CCB07CABB35CFF ] pciide          C:\Windows\system32\drivers\pciide.sys
00:35:06.0502 5936  pciide - ok
00:35:06.0525 5936  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
00:35:06.0546 5936  pcmcia - ok
00:35:06.0612 5936  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
00:35:06.0773 5936  PEAUTH - ok
00:35:06.0861 5936  [ CD05A38D166BEADE18030BAFC0C0A939 ] pla            C:\Windows\system32\pla.dll
00:35:07.0021 5936  pla - ok
00:35:07.0065 5936  [ 747BB4C31F3B6E8D1B5ED0AD61518CB5 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
00:35:07.0095 5936  PlugPlay - ok
00:35:07.0127 5936  [ 016D01D3B8FB976A193C7434BED8DCCF ] PNRPAutoReg    C:\Windows\system32\p2psvc.dll
00:35:07.0166 5936  PNRPAutoReg - ok
00:35:07.0204 5936  [ 016D01D3B8FB976A193C7434BED8DCCF ] PNRPsvc        C:\Windows\system32\p2psvc.dll
00:35:07.0247 5936  PNRPsvc - ok
00:35:07.0299 5936  [ 5EBDEC613BD377CE9A85382BE5C6B83B ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
00:35:07.0388 5936  PolicyAgent - ok
00:35:07.0438 5936  [ C04DEC5ACE67C5247B150C4223970BB7 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
00:35:07.0496 5936  PptpMiniport - ok
00:35:07.0528 5936  [ 0E3CEF5D28B40CF273281D620C50700A ] Processor      C:\Windows\system32\drivers\processr.sys
00:35:07.0631 5936  Processor - ok
00:35:07.0669 5936  [ 8B8E8F4734C5C576E3B910DB73756CF1 ] ProfSvc        C:\Windows\system32\profsvc.dll
00:35:07.0732 5936  ProfSvc - ok
00:35:07.0759 5936  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] ProtectedStorage C:\Windows\system32\lsass.exe
00:35:07.0789 5936  ProtectedStorage - ok
00:35:07.0807 5936  [ 2C8BAE55247C4E09352E870292E4D1AB ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
00:35:07.0850 5936  PSched - ok
00:35:07.0921 5936  [ CCDAC889326317792480C0A67156A1EC ] ql2300          C:\Windows\system32\drivers\ql2300.sys
00:35:08.0004 5936  ql2300 - ok
00:35:08.0027 5936  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
00:35:08.0051 5936  ql40xx - ok
00:35:08.0079 5936  [ CA61BDFD3713A7CE75F2812AFC431594 ] QWAVE          C:\Windows\system32\qwave.dll
00:35:08.0135 5936  QWAVE - ok
00:35:08.0171 5936  [ D2B3E2B7426DC23E185FBC73C8936C12 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
00:35:08.0221 5936  QWAVEdrv - ok
00:35:08.0341 5936  [ 5439B251AF73E7EFAE4B8771D7116159 ] R300            C:\Windows\system32\DRIVERS\atikmdag.sys
00:35:08.0487 5936  R300 - ok
00:35:08.0531 5936  [ BD7B30F55B3649506DD8B3D38F571D2A ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
00:35:08.0639 5936  RasAcd - ok
00:35:08.0651 5936  [ F14F4AAB9F54D099FE99192BDB100AC9 ] RasAuto        C:\Windows\System32\rasauto.dll
00:35:08.0727 5936  RasAuto - ok
00:35:08.0748 5936  [ 68B0019FEE429EC49D29017AF937E482 ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
00:35:08.0774 5936  Rasl2tp - ok
00:35:08.0791 5936  [ 11D65E29BC9D1E4114D18FE68194394C ] RasMan          C:\Windows\System32\rasmans.dll
00:35:08.0867 5936  RasMan - ok
00:35:08.0881 5936  [ CCF4E9C6CBBAC81437F88CB2AE0B6C96 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
00:35:08.0954 5936  RasPppoe - ok
00:35:08.0993 5936  [ 54129C5D9581BBEC8BD1EBD3BA813F47 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
00:35:09.0069 5936  rdbss - ok
00:35:09.0085 5936  [ 794585276B5D7FCA9F3FC15543F9F0B9 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
00:35:09.0162 5936  RDPCDD - ok
00:35:09.0200 5936  [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr          C:\Windows\system32\drivers\rdpdr.sys
00:35:09.0293 5936  rdpdr - ok
00:35:09.0301 5936  [ 980B56E2E273E19D3A9D72D5C420F008 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
00:35:09.0376 5936  RDPENCDD - ok
00:35:09.0405 5936  [ 8830E790A74A96605FABA74F9665BB3C ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
00:35:09.0495 5936  RDPWD - ok
00:35:09.0536 5936  [ 6C1A43C589EE8011A1EBFD51C01B77CE ] RemoteAccess    C:\Windows\System32\mprdim.dll
00:35:09.0628 5936  RemoteAccess - ok
00:35:09.0668 5936  [ 9A043808667C8C1893DA7275AF373F0E ] RemoteRegistry  C:\Windows\system32\regsvc.dll
00:35:09.0744 5936  RemoteRegistry - ok
00:35:09.0765 5936  [ 7EC90C316177BA3F1BCE92005264B447 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
00:35:09.0854 5936  RFCOMM - ok
00:35:09.0915 5936  [ 4D05898896EC49CF663DDA61041AB096 ] RichVideo      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
00:35:09.0936 5936  RichVideo - ok
00:35:09.0966 5936  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
00:35:10.0004 5936  RpcLocator - ok
00:35:10.0040 5936  [ 7B981222A257D076885BFFB66F19B7CE ] RpcSs          C:\Windows\system32\rpcss.dll
00:35:10.0086 5936  RpcSs - ok
00:35:10.0114 5936  [ 97E939D2128FEC5D5A3E6E79B290A2F4 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
00:35:10.0202 5936  rspndr - ok
00:35:10.0228 5936  [ 959EF612D2CCFDB6D9E443F8E3655013 ] RTL8023xp      C:\Windows\system32\DRIVERS\Rtnicxp.sys
00:35:10.0300 5936  RTL8023xp - ok
00:35:10.0370 5936  [ A1D1D3A6C17A084F13C3A5ED253D42FA ] RTL8187        C:\Windows\system32\DRIVERS\RTL8187.sys
00:35:10.0427 5936  RTL8187 - ok
00:35:10.0476 5936  [ 69013A123A00B3042C260B0056DF0152 ] s1029bus        C:\Windows\system32\DRIVERS\s1029bus.sys
00:35:10.0493 5936  s1029bus - ok
00:35:10.0536 5936  [ 1565FC31F872963FE8AF471123D8424C ] s1029mdfl      C:\Windows\system32\DRIVERS\s1029mdfl.sys
00:35:10.0550 5936  s1029mdfl - ok
00:35:10.0580 5936  [ D67A8042ECF6C983AC0E308B36603677 ] s1029mdm        C:\Windows\system32\DRIVERS\s1029mdm.sys
00:35:10.0597 5936  s1029mdm - ok
00:35:10.0638 5936  [ 9AC56F06C1E13A963C82EBD067FDF274 ] s1029mgmt      C:\Windows\system32\DRIVERS\s1029mgmt.sys
00:35:10.0655 5936  s1029mgmt - ok
00:35:10.0678 5936  [ 00C66C6BAAFB2747F15F94F15888C94A ] s1029nd5        C:\Windows\system32\DRIVERS\s1029nd5.sys
00:35:10.0693 5936  s1029nd5 - ok
00:35:10.0773 5936  [ 6FC093ABA554E45755DC2F3896B6C8D7 ] s1029obex      C:\Windows\system32\DRIVERS\s1029obex.sys
00:35:10.0797 5936  s1029obex - ok
00:35:10.0831 5936  [ 9979B0E68815394665B2109B03D15FA1 ] s1029unic      C:\Windows\system32\DRIVERS\s1029unic.sys
00:35:10.0882 5936  s1029unic - ok
00:35:10.0905 5936  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] SamSs          C:\Windows\system32\lsass.exe
00:35:10.0929 5936  SamSs - ok
00:35:10.0990 5936  [ 4BFB51CDB25D4D4B9E8FCCAB635F262E ] Samsung Update Plus C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
00:35:11.0017 5936  Samsung Update Plus ( UnsignedFile.Multi.Generic ) - warning
00:35:11.0017 5936  Samsung Update Plus - detected UnsignedFile.Multi.Generic (1)
00:35:11.0053 5936  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
00:35:11.0071 5936  sbp2port - ok
00:35:11.0116 5936  [ 565B4B9E5AD2F2F18A4F8AAFA6C06BBB ] SCardSvr        C:\Windows\System32\SCardSvr.dll
00:35:11.0205 5936  SCardSvr - ok
00:35:11.0242 5936  [ 886CEC884B5BE29AB9828B8AB46B11F7 ] Schedule        C:\Windows\system32\schedsvc.dll
00:35:11.0332 5936  Schedule - ok
00:35:11.0363 5936  [ 0600E04315FE543802A379D5D23C8BE0 ] SCPolicySvc    C:\Windows\System32\certprop.dll
00:35:11.0435 5936  SCPolicySvc - ok
00:35:11.0462 5936  [ 4339A2585708C7D9B0C0CE5AAD3DD6FF ] sdbus          C:\Windows\system32\DRIVERS\sdbus.sys
00:35:11.0533 5936  sdbus - ok
00:35:11.0560 5936  [ F7B6BF02240D0A764ADF8C8966735552 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
00:35:11.0607 5936  SDRSVC - ok
00:35:11.0631 5936  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
00:35:11.0700 5936  secdrv - ok
00:35:11.0721 5936  [ 8388C4133DDBE62AD7BC3EC9F14271ED ] seclogon        C:\Windows\system32\seclogon.dll
00:35:11.0808 5936  seclogon - ok
00:35:11.0826 5936  [ 34350AE2C1D33D21C7305F861BD8DAD8 ] SENS            C:\Windows\System32\sens.dll
00:35:11.0912 5936  SENS - ok
00:35:11.0936 5936  [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum        C:\Windows\system32\drivers\serenum.sys
00:35:12.0019 5936  Serenum - ok
00:35:12.0046 5936  [ C70D69A918B178D3C3B06339B40C2E1B ] Serial          C:\Windows\system32\drivers\serial.sys
00:35:12.0117 5936  Serial - ok
00:35:12.0146 5936  [ 450ACCD77EC5CEA720C1CDB9E26B953B ] sermouse        C:\Windows\system32\drivers\sermouse.sys
00:35:12.0177 5936  sermouse - ok
00:35:12.0202 5936  [ 78878235DA4DF0D116E86837A0A21DF8 ] SessionEnv      C:\Windows\system32\sessenv.dll
00:35:12.0277 5936  SessionEnv - ok
00:35:12.0296 5936  [ 103B79418DA647736EE95645F305F68A ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
00:35:12.0367 5936  sffdisk - ok
00:35:12.0393 5936  [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
00:35:12.0464 5936  sffp_mmc - ok
00:35:12.0485 5936  [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
00:35:12.0571 5936  sffp_sd - ok
00:35:12.0595 5936  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy        C:\Windows\system32\drivers\sfloppy.sys
00:35:12.0666 5936  sfloppy - ok
00:35:12.0698 5936  [ 9A82BF4C90B00A63150A606A1E2FD82B ] SharedAccess    C:\Windows\System32\ipnathlp.dll
00:35:12.0726 5936  SharedAccess - ok
00:35:12.0764 5936  [ B264DFA21677728613267FE63802B332 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
00:35:12.0798 5936  ShellHWDetection - ok
00:35:12.0816 5936  [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
00:35:12.0834 5936  sisagp - ok
00:35:12.0857 5936  [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
00:35:12.0874 5936  SiSRaid2 - ok
00:35:12.0904 5936  [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
00:35:12.0923 5936  SiSRaid4 - ok
00:35:12.0977 5936  [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate    C:\Program Files\Skype\Updater\Updater.exe
00:35:12.0995 5936  SkypeUpdate - ok
00:35:13.0089 5936  [ A1DCD30534835CB67733AD00175125A6 ] slsvc          C:\Windows\system32\SLsvc.exe
00:35:13.0282 5936  slsvc - ok
00:35:13.0329 5936  [ 56DA296E7B376A727E7BDC5AC7FBEE02 ] SLUINotify      C:\Windows\system32\SLUINotify.dll
00:35:13.0371 5936  SLUINotify - ok
00:35:13.0414 5936  [ 46BAF398809A0F3B2D3300A1760E4B91 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
00:35:13.0464 5936  Smb - ok
00:35:13.0504 5936  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
00:35:13.0546 5936  SNMPTRAP - ok
00:35:13.0567 5936  [ 426F9B029AA9162CECCF65369457D046 ] spldr          C:\Windows\system32\drivers\spldr.sys
00:35:13.0595 5936  spldr - ok
00:35:13.0616 5936  [ DA612EF2556776DF2630B68BF2D48935 ] Spooler        C:\Windows\System32\spoolsv.exe
00:35:13.0649 5936  Spooler - ok
00:35:13.0692 5936  [ B2EC3E1DEAC5F0A764BD3486D213A0AF ] SQLBrowser      C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
00:35:13.0712 5936  SQLBrowser - ok
00:35:13.0770 5936  [ D2F4F32B59440011174B4F8137AF4E0C ] SQLWriter      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
00:35:13.0787 5936  SQLWriter - ok
00:35:13.0809 5936  [ 038579C35F7CAD4A4BBF735DBF83277D ] srv            C:\Windows\system32\DRIVERS\srv.sys
00:35:13.0855 5936  srv - ok
00:35:13.0882 5936  [ 6971A757AF8CB5E2CBCBB76CC530DB6C ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
00:35:13.0942 5936  srv2 - ok
00:35:13.0957 5936  [ 9E1A4603B874EEBCE0298113951ABEFB ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
00:35:13.0982 5936  srvnet - ok
00:35:14.0026 5936  [ 8D3E4BAFF8B3997138C38EB1B600519A ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
00:35:14.0104 5936  SSDPSRV - ok
00:35:14.0169 5936  [ A941E099EF46E3CC12F898CBE1C39910 ] stisvc          C:\Windows\System32\wiaservc.dll
00:35:14.0261 5936  stisvc - ok
00:35:14.0301 5936  [ 3B80B4383C9BCE13279C8482734B32B2 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
00:35:14.0318 5936  swenum - ok
00:35:14.0349 5936  [ 749ADA8D6C18A08ADFEDE69CBF5DB2E0 ] swprv          C:\Windows\System32\swprv.dll
00:35:14.0441 5936  swprv - ok
00:35:14.0479 5936  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx        C:\Windows\system32\drivers\symc8xx.sys
00:35:14.0496 5936  Symc8xx - ok
00:35:14.0518 5936  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
00:35:14.0536 5936  Sym_hi - ok
00:35:14.0557 5936  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
00:35:14.0574 5936  Sym_u3 - ok
00:35:14.0622 5936  [ 451E8037E2EB6DA6BDF0A66F65D1810B ] SynTP          C:\Windows\system32\DRIVERS\SynTP.sys
00:35:14.0642 5936  SynTP - ok
00:35:14.0672 5936  [ 8F2B5FEDE18BD3C4C926CBF88E6F1264 ] SysMain        C:\Windows\system32\sysmain.dll
00:35:14.0743 5936  SysMain - ok
00:35:14.0776 5936  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
00:35:14.0831 5936  TabletInputService - ok
00:35:14.0867 5936  [ EF3DD33C740FC2F82E7E4622F1C49289 ] TapiSrv        C:\Windows\System32\tapisrv.dll
00:35:14.0944 5936  TapiSrv - ok
00:35:14.0964 5936  [ 68FA52794AE9ACC61BDE16FE0956B414 ] TBS            C:\Windows\System32\tbssvc.dll
00:35:15.0038 5936  TBS - ok
00:35:15.0097 5936  [ 4A82FA8F0DF67AA354580C3FAAF8BDE3 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
00:35:15.0184 5936  Tcpip - ok
00:35:15.0205 5936  [ 4A82FA8F0DF67AA354580C3FAAF8BDE3 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
00:35:15.0250 5936  Tcpip6 - ok
00:35:15.0277 5936  [ 5CE0C4A7B12D0067DAD527D72B68C726 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
00:35:15.0363 5936  tcpipreg - ok
00:35:15.0405 5936  [ 964248AEF49C31FA6A93201A73FFAF50 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
00:35:15.0504 5936  TDPIPE - ok
00:35:15.0527 5936  [ 7D2C1AE1648A60FCE4AA0F7982E419D3 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
00:35:15.0628 5936  TDTCP - ok
00:35:15.0661 5936  [ AB4FDE8AF4A0270A46A001C08CBCE1C2 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
00:35:15.0745 5936  tdx - ok
00:35:15.0766 5936  [ 849ED71967D45F15C3E0ABFC633FDF2A ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
00:35:15.0786 5936  TermDD - ok
00:35:15.0827 5936  [ FAD71C1E8E4047B154E899AE31EB8CAA ] TermService    C:\Windows\System32\termsrv.dll
00:35:15.0947 5936  TermService - ok
00:35:15.0988 5936  [ B264DFA21677728613267FE63802B332 ] Themes          C:\Windows\system32\shsvcs.dll
00:35:16.0020 5936  Themes - ok
00:35:16.0038 5936  [ 9DFA3A459AF0954AA85B4F7622AD87BB ] THREADORDER    C:\Windows\system32\mmcss.dll
00:35:16.0111 5936  THREADORDER - ok
00:35:16.0132 5936  [ 6BBA0582C0025D43729A1112D3B57897 ] TrkWks          C:\Windows\System32\trkwks.dll
00:35:16.0208 5936  TrkWks - ok
00:35:16.0264 5936  [ 34E388A395FEDBA1D0511ED39BBF4074 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
00:35:16.0285 5936  TrustedInstaller - ok
00:35:16.0327 5936  [ 29F0ECA726F0D51F7E048BDB0B372F29 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
00:35:16.0398 5936  tssecsrv - ok
00:35:16.0446 5936  [ 65E953BC0084D44498B51F59784D2A82 ] tunmp          C:\Windows\system32\DRIVERS\tunmp.sys
00:35:16.0479 5936  tunmp - ok
00:35:16.0508 5936  [ 4A39BDA5E0FD30BDF4884F9D33AE6105 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
00:35:16.0532 5936  tunnel - ok
00:35:16.0570 5936  [ C3ADE15414120033A36C0F293D4A4121 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
00:35:16.0589 5936  uagp35 - ok
00:35:16.0617 5936  [ 6348DA98707CEDA8A0DFB05820E17732 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
00:35:16.0708 5936  udfs - ok
00:35:16.0743 5936  [ 24A333F4F14DCFB6FF6D5A1B9E5D79DD ] UI0Detect      C:\Windows\system32\UI0Detect.exe
00:35:16.0785 5936  UI0Detect - ok
00:35:16.0808 5936  [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
00:35:16.0827 5936  uliagpkx - ok
00:35:16.0855 5936  [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci        C:\Windows\system32\drivers\uliahci.sys
00:35:16.0878 5936  uliahci - ok
00:35:16.0908 5936  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
00:35:16.0928 5936  UlSata - ok
00:35:16.0959 5936  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2        C:\Windows\system32\drivers\ulsata2.sys
00:35:16.0982 5936  ulsata2 - ok
00:35:17.0012 5936  [ 3FB78F1D1DD86D87BECECD9DFFA24DD9 ] umbus          C:\Windows\system32\DRIVERS\umbus.sys
00:35:17.0116 5936  umbus - ok
00:35:17.0148 5936  [ 8EB871A3DEB6B3D5A85EB6DDFC390B59 ] upnphost        C:\Windows\System32\upnphost.dll
00:35:17.0258 5936  upnphost - ok
00:35:17.0331 5936  [ F6BF998AE33E3FB6C7D27F0560F1173F ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
00:35:17.0420 5936  usbaudio - ok
00:35:17.0466 5936  [ 03B01E8DBD2DA2B49157B7E51912AAF2 ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
00:35:17.0500 5936  usbccgp - ok
00:35:17.0540 5936  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
00:35:17.0612 5936  usbcir - ok
00:35:17.0650 5936  [ 2F83363F98484F8EDAF49F9B41520D14 ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
00:35:17.0689 5936  usbehci - ok
00:35:17.0717 5936  [ 14D2A4DCD92C0B3368667AED6893463D ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
00:35:17.0758 5936  usbhub - ok
00:35:17.0782 5936  [ 51DC36722172D45F2F935CE5CC18A812 ] usbohci        C:\Windows\system32\DRIVERS\usbohci.sys
00:35:17.0820 5936  usbohci - ok
00:35:17.0838 5936  [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
00:35:17.0944 5936  usbprint - ok
00:35:17.0975 5936  [ 7887CE56934E7F104E98C975F47353C5 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:35:18.0009 5936  USBSTOR - ok
00:35:18.0035 5936  [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
00:35:18.0122 5936  usbuhci - ok
00:35:18.0160 5936  [ 0A6B81F01BC86399482E27E6FDA7B33B ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
00:35:18.0232 5936  usbvideo - ok
00:35:18.0269 5936  [ F79D0D7C9004474CB42746D9B2C30A2B ] UxSms          C:\Windows\System32\uxsms.dll
00:35:18.0344 5936  UxSms - ok
00:35:18.0374 5936  [ C9D0BAFEE0D0A2681F048CA61BC0DA96 ] vds            C:\Windows\System32\vds.exe
00:35:18.0441 5936  vds - ok
00:35:18.0479 5936  [ 7D92BE0028ECDEDEC74617009084B5EF ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
00:35:18.0549 5936  vga - ok
00:35:18.0592 5936  [ 17A8F877314E4067F8C8172CC6D9101C ] VgaSave        C:\Windows\System32\drivers\vga.sys
00:35:18.0663 5936  VgaSave - ok
00:35:18.0690 5936  [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp          C:\Windows\system32\drivers\viaagp.sys
00:35:18.0709 5936  viaagp - ok
00:35:18.0737 5936  [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7          C:\Windows\system32\drivers\viac7.sys
00:35:18.0825 5936  ViaC7 - ok
00:35:18.0844 5936  [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide          C:\Windows\system32\drivers\viaide.sys
00:35:18.0862 5936  viaide - ok
00:35:18.0870 5936  VMC302 - ok
00:35:18.0894 5936  [ FD16FAC15F9F165AC19A618E7B391F5C ] volmgr          C:\Windows\system32\drivers\volmgr.sys
00:35:18.0912 5936  volmgr - ok
00:35:18.0942 5936  [ 294DA8D3F965F6A8DB934A83C7B461FF ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
00:35:18.0968 5936  volmgrx - ok
00:35:18.0991 5936  [ 80DC0C9BCB579ED9815001A4D37CBFD5 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
00:35:19.0015 5936  volsnap - ok
00:35:19.0044 5936  [ D984439746D42B30FC65A4C3546C6829 ] vsmraid        C:\Windows\system32\drivers\vsmraid.sys
00:35:19.0064 5936  vsmraid - ok
00:35:19.0137 5936  [ E0E29D9EF2524ABD11749C7C2FD7F607 ] VSS            C:\Windows\system32\vssvc.exe
00:35:19.0241 5936  VSS - ok
00:35:19.0267 5936  [ 62B0D0F6F5580D9D0DFA5E0B466FF2ED ] W32Time        C:\Windows\system32\w32time.dll
00:35:19.0346 5936  W32Time - ok
00:35:19.0378 5936  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
00:35:19.0448 5936  WacomPen - ok
00:35:19.0473 5936  [ 6798C1209A53B5A0DED8D437C45145FF ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
00:35:19.0497 5936  Wanarp - ok
00:35:19.0503 5936  [ 6798C1209A53B5A0DED8D437C45145FF ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
00:35:19.0529 5936  Wanarpv6 - ok
00:35:19.0547 5936  [ C1B19162E0509CEAB4CDF664E139D956 ] wcncsvc        C:\Windows\System32\wcncsvc.dll
00:35:19.0599 5936  wcncsvc - ok
00:35:19.0629 5936  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
00:35:19.0684 5936  WcsPlugInService - ok
00:35:19.0713 5936  [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd              C:\Windows\system32\drivers\wd.sys
00:35:19.0730 5936  Wd - ok
00:35:19.0781 5936  [ 7B5F66E4A2219C7D9DAF9E738480E534 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
00:35:19.0829 5936  Wdf01000 - ok
00:35:19.0845 5936  [ 2A424B89B14EF17A3D06BCB5A8F79601 ] WdiServiceHost  C:\Windows\system32\wdi.dll
00:35:19.0894 5936  WdiServiceHost - ok
00:35:19.0901 5936  [ 2A424B89B14EF17A3D06BCB5A8F79601 ] WdiSystemHost  C:\Windows\system32\wdi.dll
00:35:19.0932 5936  WdiSystemHost - ok
00:35:19.0956 5936  [ 01E41C264EEDCB827820A1909162579F ] WebClient      C:\Windows\System32\webclnt.dll
00:35:19.0985 5936  WebClient - ok
00:35:20.0002 5936  [ 9CF67FF7F8D34CBF115D0C278B9F74AA ] Wecsvc          C:\Windows\system32\wecsvc.dll
00:35:20.0078 5936  Wecsvc - ok
00:35:20.0101 5936  [ B68CAB45DB1DAB59D92ACADFAD6364A8 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
00:35:20.0181 5936  wercplsupport - ok
00:35:20.0202 5936  [ 36BA0707680EF4236FD752BEE982CC25 ] WerSvc          C:\Windows\System32\WerSvc.dll
00:35:20.0285 5936  WerSvc - ok
00:35:20.0347 5936  [ 0D5AD0E71FF5DDAC5DD2F443B499ABD0 ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
00:35:20.0379 5936  WinDefend - ok
00:35:20.0389 5936  WinHttpAutoProxySvc - ok
00:35:20.0430 5936  [ 38A7B89DE4E3417C122317949667FDD8 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
00:35:20.0513 5936  Winmgmt - ok
00:35:20.0551 5936  [ 3F6823040030C3E4DA1CF11CD40B7534 ] WinRM          C:\Windows\system32\WsmSvc.dll
00:35:20.0694 5936  WinRM - ok
00:35:20.0769 5936  [ 7640ACEA41348BFEF34B76E245501261 ] Wlansvc        C:\Windows\System32\wlansvc.dll
00:35:20.0871 5936  Wlansvc - ok
00:35:20.0944 5936  [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
00:35:21.0027 5936  WmiAcpi - ok
00:35:21.0068 5936  [ A279323BEE5FFFAFDA222910BCE92132 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
00:35:21.0128 5936  wmiApSrv - ok
00:35:21.0221 5936  [ ACB2E63D50157E3EA7140F29D9E76A48 ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
00:35:21.0315 5936  WMPNetworkSvc - ok
00:35:21.0339 5936  [ 3D3B3B80C12ABE506F56930C46422C28 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
00:35:21.0401 5936  WPCSvc - ok
00:35:21.0419 5936  [ C24844A1D0D9528B19D5BC266B8CD572 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
00:35:21.0472 5936  WPDBusEnum - ok
00:35:21.0506 5936  [ 2D27171B16A577EF14C1273668753485 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
00:35:21.0608 5936  WpdUsb - ok
00:35:21.0634 5936  [ 84620AECDCFD2A7A14E6263927D8C0ED ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
00:35:21.0724 5936  ws2ifsl - ok
00:35:21.0744 5936  [ F97CBB919AF6D0A6643D1A59C15014D1 ] wscsvc          C:\Windows\System32\wscsvc.dll
00:35:21.0790 5936  wscsvc - ok
00:35:21.0798 5936  WSearch - ok
00:35:22.0357 5936  [ 6298277B73C77FA99106B271A7525163 ] wuauserv        C:\Windows\system32\wuaueng.dll
00:35:22.0473 5936  wuauserv - ok
00:35:22.0514 5936  [ A2AAFCC8A204736296D937C7C545B53F ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
00:35:22.0611 5936  WUDFRd - ok
00:35:22.0651 5936  [ DB5BF5AAB72B1B99B5331231D09EBB26 ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
00:35:22.0728 5936  wudfsvc - ok
00:35:22.0790 5936  [ ADE7A4943003020216952B56A6741EC7 ] yukonwlh        C:\Windows\system32\DRIVERS\yk60x86.sys
00:35:22.0844 5936  yukonwlh - ok
00:35:22.0869 5936  ================ Scan global ===============================
00:35:22.0929 5936  [ 8CD98A8EC9CADAF4E051CDCAC15C96C4 ] C:\Windows\system32\basesrv.dll
00:35:22.0978 5936  [ E3F137ADC0A9D7F3A2E4F557272FE6B3 ] C:\Windows\system32\winsrv.dll
00:35:23.0011 5936  [ E3F137ADC0A9D7F3A2E4F557272FE6B3 ] C:\Windows\system32\winsrv.dll
00:35:23.0037 5936  [ 329CF3C97CE4C19375C8ABCABAE258B0 ] C:\Windows\system32\services.exe
00:35:23.0044 5936  [Global] - ok
00:35:23.0045 5936  ================ Scan MBR ==================================
00:35:23.0063 5936  [ 61A349592C4728853F4A90FF78F7628E ] \Device\Harddisk0\DR0
00:35:23.0667 5936  \Device\Harddisk0\DR0 - ok
00:35:23.0668 5936  ================ Scan VBR ==================================
00:35:23.0674 5936  [ 47C6E4876CF829720FFCFEC341102BA5 ] \Device\Harddisk0\DR0\Partition1
00:35:23.0677 5936  \Device\Harddisk0\DR0\Partition1 - ok
00:35:23.0701 5936  [ B27E1188341E3C69AFC122F9BFB0FD30 ] \Device\Harddisk0\DR0\Partition2
00:35:23.0704 5936  \Device\Harddisk0\DR0\Partition2 - ok
00:35:23.0705 5936  ============================================================
00:35:23.0705 5936  Scan finished
00:35:23.0705 5936  ============================================================
00:35:23.0727 4444  Detected object count: 4
00:35:23.0727 4444  Actual detected object count: 4
00:35:47.0550 4444  CVPNDRVA ( UnsignedFile.Multi.Generic ) - skipped by user
00:35:47.0550 4444  CVPNDRVA ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:35:47.0555 4444  NPF_devolo ( UnsignedFile.Multi.Generic ) - skipped by user
00:35:47.0555 4444  NPF_devolo ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:35:47.0560 4444  OMSI download service ( UnsignedFile.Multi.Generic ) - skipped by user
00:35:47.0560 4444  OMSI download service ( UnsignedFile.Multi.Generic ) - User select action: Skip
00:35:47.0566 4444  Samsung Update Plus ( UnsignedFile.Multi.Generic ) - skipped by user
00:35:47.0566 4444  Samsung Update Plus ( UnsignedFile.Multi.Generic ) - User select action: Skip

ich hoffe das passt alles so.
Lg Sophie

cosinus 04.02.2013 10:57

Ok, sieht soweit gut aus. Mach bitte noch ein Log mit GMER und poste es


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:10 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131